Hi Splunkers,
Is there a breakdown of logs required for Splunk ES Content updates?
I have created my own list already but hoping there is some resource where it is updated regularly?
Thanks,
There are a wide range of detections/analytic stories in the ESCU app - it really depends on what your use-cases and requirements are as to which datasources you will need to onboard.
Check out https://research.splunk.com/sources/ for a full list of datasources used by the ESCU app as well as Analytic Stories (https://research.splunk.com/stories/) and Detections (https://research.splunk.com/detections/) which both show which sources are required for them.
This will then help your onboarding process. I would also recommend checking out SEC1638 - From Request to Response: Mastering Security Data Onboarding
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing
Hi there,
Not sure I understand your questions correctly...
If you are looking for the location where the updates are stored this page can help https://help.splunk.com/en/splunk-enterprise-security-8/security-content-update/how-to-use-splunk-se...
If you are looking for what kind of logs you need to feed a correlation search check the search itself, see which data model, tags , and or eventtypes it uses and normalise the data/logs using the CIM https://help.splunk.com/en/data-management/common-information-model/6.1/using-the-common-information...
Hope this helps ...
cheers, MuS