Splunk Enterprise Security

What is the functionality of Extreme Search Visualization outside of Splunk Enterprise Security?

stmcmahon_splun
Splunk Employee
Splunk Employee

Hello

Had someone ask:

Extreme Search Visualization (XSV), is designed as a "helper" app for Scianta Analytics' Extreme Search for Splunk."

Can I run extreme search commands and create concepts and contexts? How different is the functionality of this standalone app vs. the Enterprise Security suite?

0 Karma
1 Solution

mcormier_splunk
Splunk Employee
Splunk Employee

Extreme Search Visualization provides dashboards and wizards for creating/viewing/managing contexts and concepts. In addition, there are a couple of new ways to create contexts, Anomaly-Driven (AD) and Crossover-Driven (CD).

The XSV app is an "add on" to Extreme Search (XS). You need XS to run most of the commands/dashboards/wizards in XSV. Both apps will work outside of ES, and are not ES-dependent.

Please let me know if you have more questions about XSV, its commands, or Extreme Search.

View solution in original post

mcormier_splunk
Splunk Employee
Splunk Employee

Extreme Search Visualization provides dashboards and wizards for creating/viewing/managing contexts and concepts. In addition, there are a couple of new ways to create contexts, Anomaly-Driven (AD) and Crossover-Driven (CD).

The XSV app is an "add on" to Extreme Search (XS). You need XS to run most of the commands/dashboards/wizards in XSV. Both apps will work outside of ES, and are not ES-dependent.

Please let me know if you have more questions about XSV, its commands, or Extreme Search.

LukeMurphey
Champion

Its really no different (at least not significantly); its just bundled with ES. You should be able use it just fine.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...