Splunk Enterprise Security

Logs required for Splunk ES Content Update?

david_monaghan
Engager

Hi Splunkers,

 

Is there a breakdown of logs required for Splunk ES Content updates?

 

I have created my own list already but hoping there is some resource where it is updated regularly?

 

Thanks,

 

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @david_monaghan 

There are a wide range of detections/analytic stories in the ESCU app - it really depends on what your use-cases and requirements are as to which datasources you will need to onboard. 

Check out https://research.splunk.com/sources/ for a full list of datasources used by the ESCU app as well as Analytic Stories (https://research.splunk.com/stories/) and Detections (https://research.splunk.com/detections/) which both show which sources are required for them.

This will then help your onboarding process. I would also recommend checking out SEC1638 - From Request to Response: Mastering Security Data Onboarding 

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi there,

Not sure I understand your questions correctly...

If you are looking for the location where the updates are stored this page can help https://help.splunk.com/en/splunk-enterprise-security-8/security-content-update/how-to-use-splunk-se...

If you are looking for what kind of logs you need to feed a correlation search check the search itself, see which  data model, tags , and or eventtypes it uses and normalise the data/logs using the CIM https://help.splunk.com/en/data-management/common-information-model/6.1/using-the-common-information...

 

Hope this helps ...

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...