Splunk Enterprise Security

Splunk Enterprise Security Content Update and ES documentation inconsequence

alekwisnia
Explorer

User Guide for ESCU version 3.0.5 (https://docs.splunk.com/Documentation/ESSOC/3.0.5/user/ConfigureSplunkEnterpriseSecurity(ES)touseMLT...) refers to ES User Guide version 5.2.2 (https://docs.splunk.com/Documentation/ES/5.2.2/Install/ImportCustomApps#Import_add-ons_with_a_differ...) on how to install Custom Apps, in this case MLTK. 

The problem is, the same ES User Guide for current ES version (6.2.0) does not exist. I tried to follow the ESCU guide and configure "App Imports Update" but was unable to edit "update_es" input.

Shouldn't this be updated? What is the correct configuration of MLTK for ESCU?

0 Karma

richgalloway
SplunkTrust
SplunkTrust
Enterprise Security doesn't have the app import feature in version 6+. Apps are imported based on their security settings like with other Splunk apps.
Also, ES uses MLTK by default so there's no need to configure it to do so.
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...

Index This | What can you do to make 55,555 equal 500?

April 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...