Splunk Enterprise Security

What is the solution for real-time dataset to be ingested in Splunk Enterprise Security?

aydinmo
Explorer

Thank you all in advance! Actually, I have built a lab environment (AWS) and installed the ES APP (Enterprise Security). Now, I am looking for a solution to have access to the required data (real-time) which can be used in ES. I tried to install the Eventgen and make it work, but it does not seem to be an easy procedure. Could you please provide me a straight forward solution.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...