I have used that search tutorials for splunk.
Is there any similar one splunk ES?!?!
For splunk, there is a tutorials data zip file splunk provides. For learning ES, is there any data dump to play with?!?!
Thx..
Your best bet is to use Eventgen data. A lot of TA's out there, such as Cisco ASA, Blue Coat Proxy and Windows have a "samples" directory and an eventgen.conf file that Eventgen can use to create sample data for your environment. As you add more eventgen sources into ES, the more you'll light up the dashboards and see the functionality.
That being said, ES has quite a different knowledge requirement to Splunk Core, so this shouldn't be a replacement for undertaking ES training.
Absolutely - try out the Event Generator app.
https://splunkbase.splunk.com/app/1924/
It should generate some data to light up ES to learn on it.
Also, check out the BOTS (Boss of the SOC) v1 competition dataset, as well.
https://github.com/splunk/botsv1
Cheers.
Your best bet is to use Eventgen data. A lot of TA's out there, such as Cisco ASA, Blue Coat Proxy and Windows have a "samples" directory and an eventgen.conf file that Eventgen can use to create sample data for your environment. As you add more eventgen sources into ES, the more you'll light up the dashboards and see the functionality.
That being said, ES has quite a different knowledge requirement to Splunk Core, so this shouldn't be a replacement for undertaking ES training.