Splunk Enterprise Security

How to generate a report based on utilisation of Enterprise Security

cYcJo7
Engager

Hello,

 

is it possible to analyse the utilisation of enterprise security, I assume it is currently not used in our company, but I would like to be able to prove this in statistics

 

Thanks

Pad

Labels (1)
0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

Again - there are several different approaches you can have about "using ES" but what I'd do to get a rough idea if the solution is indeed being used:

1. Check if it's configured - are there correlation searches defined, are there user/asset mappings defined/synchronised, are sources decently onboarded (CIM-compliant)

2. Does anyone actually open ES app views in webui (you should be able to find it in internal logs).

3. What is the status of your notables and investigations - do you see any traces of anyone working on them?

4. What is the version of your ESCU app? How long ago it's been updated?

View solution in original post

0 Karma

cYcJo7
Engager

Thank you very much, that has helped me.

Have a good one

0 Karma

cYcJo7
Engager

Thank you for your quick reply, I would like to know if Enterprise security is used at all in our company. So is it used 1-2 times a year or has it only been used 10 times in the last 3 months?

0 Karma

PickleRick
SplunkTrust
SplunkTrust

#define <utilisation> please

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Again - there are several different approaches you can have about "using ES" but what I'd do to get a rough idea if the solution is indeed being used:

1. Check if it's configured - are there correlation searches defined, are there user/asset mappings defined/synchronised, are sources decently onboarded (CIM-compliant)

2. Does anyone actually open ES app views in webui (you should be able to find it in internal logs).

3. What is the status of your notables and investigations - do you see any traces of anyone working on them?

4. What is the version of your ESCU app? How long ago it's been updated?

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...