Splunk Enterprise Security

Splunk enterprise security user acceptance test, test use cases

kiranhar
Explorer

We deploying Splunk enterprise security ( SIEM) solution) and it is in the final implementation stage. does anyone have user acceptance test use cases to check the implementation whether done as per the best practices and required correlation are configured and they are working?

So I wanted to check including system, performance, implementation, use cases, correlations, alerts, search engine and other if anything important to test and confirm that the vendor has successfully implemented the Splunk.

Please help.

0 Karma

mdessus_splunk
Splunk Employee
Splunk Employee

Many ways to anwser:

  • Do manual test on specific use case
  • Use intrusive testing tools
  • Ask a pen testing company to do a intrusive test against your IT
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...