Splunk Enterprise Security

Splunk Enterprise security & ESCU: Customization of ESCU and upgrades

koshyk
Super Champion

hi folks, the scenario is like below

- have Enterprise security (ESS) in Splunk cloud + ESCU (content updates) as part of it
- if we enable a ESCU detection it works all good.
- we need to modify the ESCU slightly with a standard field and also the name of the search to fit existing organisation policy
- The uuid remain the same

  1. What will happen when the next ESCU update comes? Will it overwrite the custom changes?
  2. What is the actual ESCU update looking for? is it looking for 'search name' or the 'search id (uuid)?'?

 

What will happen when the next ESCU update comes?

Labels (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @koshyk 

Are you currently using the rules from ESCU without modification at all (e.g. just enabling the search)? 

If you make changes to the ESCU rule/search then the changes will be applied to the ./local/savedsearches.conf on your Splunk deployment. These changes will not be overwritten with future changes to the published ESCU app, however note that this could have the opposite effect as changes made to resolve issues might not take affect. 

Only the modified keys will be updated in savedsearches.conf - so if you modify the actual search then future changes to the search from ESCU will not be applied.

A lot of users opt to clone the ESCU rules and apply their organisation name as a prefix to the rules, this means they can always compare between the current and their custom ESCU rule. 

There is also an app on Splunkbase (ESCU Companion App) which looks like a good way to monitor changes between cloned rules and the current ESCU definitions.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

 

View solution in original post

koshyk
Super Champion

THANKS for the ESCU companion app hint. That's quite a good idea alongside an automatic merge concept I'm developing and producing a report for Analyst what to do. thanks for that and will mark as answered

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @koshyk 

Are you currently using the rules from ESCU without modification at all (e.g. just enabling the search)? 

If you make changes to the ESCU rule/search then the changes will be applied to the ./local/savedsearches.conf on your Splunk deployment. These changes will not be overwritten with future changes to the published ESCU app, however note that this could have the opposite effect as changes made to resolve issues might not take affect. 

Only the modified keys will be updated in savedsearches.conf - so if you modify the actual search then future changes to the search from ESCU will not be applied.

A lot of users opt to clone the ESCU rules and apply their organisation name as a prefix to the rules, this means they can always compare between the current and their custom ESCU rule. 

There is also an app on Splunkbase (ESCU Companion App) which looks like a good way to monitor changes between cloned rules and the current ESCU definitions.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

 

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...