Splunk Enterprise Security

How to generate a report based on utilisation of Enterprise Security

cYcJo7
Engager

Hello,

 

is it possible to analyse the utilisation of enterprise security, I assume it is currently not used in our company, but I would like to be able to prove this in statistics

 

Thanks

Pad

Labels (1)
0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

Again - there are several different approaches you can have about "using ES" but what I'd do to get a rough idea if the solution is indeed being used:

1. Check if it's configured - are there correlation searches defined, are there user/asset mappings defined/synchronised, are sources decently onboarded (CIM-compliant)

2. Does anyone actually open ES app views in webui (you should be able to find it in internal logs).

3. What is the status of your notables and investigations - do you see any traces of anyone working on them?

4. What is the version of your ESCU app? How long ago it's been updated?

View solution in original post

0 Karma

cYcJo7
Engager

Thank you very much, that has helped me.

Have a good one

0 Karma

cYcJo7
Engager

Thank you for your quick reply, I would like to know if Enterprise security is used at all in our company. So is it used 1-2 times a year or has it only been used 10 times in the last 3 months?

0 Karma

PickleRick
SplunkTrust
SplunkTrust

#define <utilisation> please

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Again - there are several different approaches you can have about "using ES" but what I'd do to get a rough idea if the solution is indeed being used:

1. Check if it's configured - are there correlation searches defined, are there user/asset mappings defined/synchronised, are sources decently onboarded (CIM-compliant)

2. Does anyone actually open ES app views in webui (you should be able to find it in internal logs).

3. What is the status of your notables and investigations - do you see any traces of anyone working on them?

4. What is the version of your ESCU app? How long ago it's been updated?

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...