Is it possible to get some simulation data for ESCU? Right now all searches just return nothing for our instance.
Or how can we use makeresults to generate some simulation data for ESCU?
Thank you very much for your help!
if you use the ESCU 2.0 onwards, you can navigate to the 'Analytic Story Detail' menu, select a story and submit 'Configure in ES'. This will create/enable required correlation search. You would need to ensure the sourcetype used etc..is matching with your implementation (or adjust/update it as per your env).
Sorry, could you pls tell me what is ESCU?
That is the Splunk Enterprise Security Content Update or ESCU, meow details here
https://docs.splunk.com/Documentation/ESSOC/latest/user/About
cheers, MuS