Splunk Enterprise Security

Tweek Enterprise Security when having few log inputs

b_chris21
Communicator

Hello everyone,

i am using Splunk Enterprise Security but at the moment because I don't have enough logs (only from Suricata) I use only ES's "Incident Review" to track notable events and create investigations. This is quite handy while waiting for new logs to be input and use 100% of Enterprise Security app.

Since I only use 5% of its capabilites I would like to "kill" most of resource consuming functions from ES. Any ideas what shall I deactivate (eg. accelerated searches, apps like threat-Intel since I am offline etc)?

Thanks a lot,

Chris

0 Karma
1 Solution

adonio
Ultra Champion

Hello there,

couple of things you can do right away are:
disable DM accelerations for indexes that dont contain any data / enable only relevant DMs and map to the right index
follow this document to manage as you see fit (many links to possible tweaks)
https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Managingcontent

hope it helps

View solution in original post

adonio
Ultra Champion

Hello there,

couple of things you can do right away are:
disable DM accelerations for indexes that dont contain any data / enable only relevant DMs and map to the right index
follow this document to manage as you see fit (many links to possible tweaks)
https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Managingcontent

hope it helps

Get Updates on the Splunk Community!

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...

Admin Console: A Single, Unified Interface for All Your Cloud Admin Needs

WATCH NOWJoin us to learn how the admin console can save you time and give you more control over the Splunk® ...