Splunk Enterprise Security

Splunk Enterprise Security

kkkelvinkk
New Member

Hi,

I have installed a splunk enterprise trial and also requested Splunk Enterprise Security. I noticed that when I try a simple search "fail* password" in both platform, the fields that available are different. In Splunk Enterprise Security, the fields "dest, src, user" are being shown. I would like to ask is these fields are being known to splunk after installing Splunk Enterprise Security ?
Thanks all.

0 Karma
1 Solution

sfefcu
Path Finder

The Splunk Enterprise Security App installs several security-specific apps and configured inputs. The idea is to make it (Common Information Model) CIM-compliant. The Common Information Model (Splunk_SA_CIM) is one of the apps that is installed. Those fields (dest, src, user) are part of that app.

View solution in original post

0 Karma

kkkelvinkk
New Member

Thanks. I have installed the CIM, but CIM alone sms did not extract those fields. I also install Splunk Add-on for Unix and Linux and the fields are available now.

0 Karma

sfefcu
Path Finder

The Splunk Enterprise Security App installs several security-specific apps and configured inputs. The idea is to make it (Common Information Model) CIM-compliant. The Common Information Model (Splunk_SA_CIM) is one of the apps that is installed. Those fields (dest, src, user) are part of that app.

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...