Splunk Enterprise Security

Splunk Enterprise Security tutorials and sample data dump

inventsekar
SplunkTrust
SplunkTrust

I have used that search tutorials for splunk.
Is there any similar one splunk ES?!?!

For splunk, there is a tutorials data zip file splunk provides. For learning ES, is there any data dump to play with?!?!

Thx..

Labels (1)
0 Karma
1 Solution

mgaudie_splunk
Splunk Employee
Splunk Employee

Your best bet is to use Eventgen data. A lot of TA's out there, such as Cisco ASA, Blue Coat Proxy and Windows have a "samples" directory and an eventgen.conf file that Eventgen can use to create sample data for your environment. As you add more eventgen sources into ES, the more you'll light up the dashboards and see the functionality.

That being said, ES has quite a different knowledge requirement to Splunk Core, so this shouldn't be a replacement for undertaking ES training.

View solution in original post

Splunker
Communicator

Absolutely - try out the Event Generator app.

https://splunkbase.splunk.com/app/1924/

It should generate some data to light up ES to learn on it.

Also, check out the BOTS (Boss of the SOC) v1 competition dataset, as well.

https://github.com/splunk/botsv1

Cheers.

mgaudie_splunk
Splunk Employee
Splunk Employee

Your best bet is to use Eventgen data. A lot of TA's out there, such as Cisco ASA, Blue Coat Proxy and Windows have a "samples" directory and an eventgen.conf file that Eventgen can use to create sample data for your environment. As you add more eventgen sources into ES, the more you'll light up the dashboards and see the functionality.

That being said, ES has quite a different knowledge requirement to Splunk Core, so this shouldn't be a replacement for undertaking ES training.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology ...

At .conf26, Don’t Just See What’s Next. Help Shape It at Innovation Labs.

Long before a new capability reaches the keynote stage, it begins as an idea waiting to be tested. At ...

Data Management Digest – August 2026

Data Management Digest   Welcome to the August 2026 edition of Data Management Digest! August was a big month ...