Splunk Enterprise Security

Splunk enterprise security user acceptance test, test use cases

kiranhar
Explorer

We deploying Splunk enterprise security ( SIEM) solution) and it is in the final implementation stage. does anyone have user acceptance test use cases to check the implementation whether done as per the best practices and required correlation are configured and they are working?

So I wanted to check including system, performance, implementation, use cases, correlations, alerts, search engine and other if anything important to test and confirm that the vendor has successfully implemented the Splunk.

Please help.

0 Karma

mdessus_splunk
Splunk Employee
Splunk Employee

Many ways to anwser:

  • Do manual test on specific use case
  • Use intrusive testing tools
  • Ask a pen testing company to do a intrusive test against your IT
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...