Splunk Enterprise Security

Splunk ES tutorials and sample data dump

inventsekar
SplunkTrust
SplunkTrust

I have used that search tutorials for splunk.
Is there any similar one splunk ES?!?!

For splunk, there is a tutorials data zip file splunk provides. For learning ES, is there any data dump to play with?!?!

Thx..

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
1 Solution

mgaudie_splunk
Splunk Employee
Splunk Employee

Your best bet is to use Eventgen data. A lot of TA's out there, such as Cisco ASA, Blue Coat Proxy and Windows have a "samples" directory and an eventgen.conf file that Eventgen can use to create sample data for your environment. As you add more eventgen sources into ES, the more you'll light up the dashboards and see the functionality.

That being said, ES has quite a different knowledge requirement to Splunk Core, so this shouldn't be a replacement for undertaking ES training.

View solution in original post

Splunker
Communicator

Absolutely - try out the Event Generator app.

https://splunkbase.splunk.com/app/1924/

It should generate some data to light up ES to learn on it.

Also, check out the BOTS (Boss of the SOC) v1 competition dataset, as well.

https://github.com/splunk/botsv1

Cheers.

mgaudie_splunk
Splunk Employee
Splunk Employee

Your best bet is to use Eventgen data. A lot of TA's out there, such as Cisco ASA, Blue Coat Proxy and Windows have a "samples" directory and an eventgen.conf file that Eventgen can use to create sample data for your environment. As you add more eventgen sources into ES, the more you'll light up the dashboards and see the functionality.

That being said, ES has quite a different knowledge requirement to Splunk Core, so this shouldn't be a replacement for undertaking ES training.

First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...