Splunk Enterprise Security

Splunk Enterprise Security Content Update and ES documentation inconsequence

alekwisnia
Explorer

User Guide for ESCU version 3.0.5 (https://docs.splunk.com/Documentation/ESSOC/3.0.5/user/ConfigureSplunkEnterpriseSecurity(ES)touseMLT...) refers to ES User Guide version 5.2.2 (https://docs.splunk.com/Documentation/ES/5.2.2/Install/ImportCustomApps#Import_add-ons_with_a_differ...) on how to install Custom Apps, in this case MLTK. 

The problem is, the same ES User Guide for current ES version (6.2.0) does not exist. I tried to follow the ESCU guide and configure "App Imports Update" but was unable to edit "update_es" input.

Shouldn't this be updated? What is the correct configuration of MLTK for ESCU?

0 Karma

richgalloway
SplunkTrust
SplunkTrust
Enterprise Security doesn't have the app import feature in version 6+. Apps are imported based on their security settings like with other Splunk apps.
Also, ES uses MLTK by default so there's no need to configure it to do so.
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...