Splunk Enterprise Security

How to make sense of data

michael_lee
Path Finder

So we have various types of logs that Splunk collects. E.g. Windows events, web server logs, syslogs, cisco switches and the likes. How do you make sense of such a huge amount of data that comes from different devices to find what you want, with context? Do you use Enterprise Security ? Or do you craft your own search algorithms? thanks

0 Karma
1 Solution

mdessus_splunk
Splunk Employee
Splunk Employee

Hi Michael,

It depends what you're looking for and your environment: you could just start with a few basic rules and dashboards (security or not) if you do not have much security background or are too busy. You might add ES later to have some more in depth view of your security, or add it at the beginning if you have enough people with security skills.
Keep in mind you should go step after steps, and that even with ES, you will need to adapt it to your company and threats.

View solution in original post

fdi01
Motivator

mdessus_splunk
Splunk Employee
Splunk Employee

Hi Michael,

It depends what you're looking for and your environment: you could just start with a few basic rules and dashboards (security or not) if you do not have much security background or are too busy. You might add ES later to have some more in depth view of your security, or add it at the beginning if you have enough people with security skills.
Keep in mind you should go step after steps, and that even with ES, you will need to adapt it to your company and threats.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...