Splunk Enterprise Security

What are the steps to fully enable ES in a company?

danielbb
Motivator

We have ES installed and we managed to map a couple of our indexes to the proper data models (using the tags) which we accelerated and then the corresponding dashboards show data and it does look impressive ; -)

So, we started the process. Now I wonder what we need to do to fully enable ES here.

Tags (1)
0 Karma
1 Solution

starcher
Influencer

I would recommend you begin with the ES training on using and administering it. ES is a platform application there is no simple list of steps.

https://www.splunk.com/en_us/training/courses/using-splunk-enterprise-security.html
https://www.splunk.com/en_us/training/courses/administering-splunk-enterprise-security.html

View solution in original post

starcher
Influencer

I would recommend you begin with the ES training on using and administering it. ES is a platform application there is no simple list of steps.

https://www.splunk.com/en_us/training/courses/using-splunk-enterprise-security.html
https://www.splunk.com/en_us/training/courses/administering-splunk-enterprise-security.html

danielbb
Motivator

Thank you @starcher.

0 Karma

starcher
Influencer

The docs on ES are also good. skimming them is helpful https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Formatassetoridentitylist

danielbb
Motivator

Thank you!!

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...