Splunk Enterprise Security

What is the solution for real-time dataset to be ingested in Splunk Enterprise Security?

aydinmo
Explorer

Thank you all in advance! Actually, I have built a lab environment (AWS) and installed the ES APP (Enterprise Security). Now, I am looking for a solution to have access to the required data (real-time) which can be used in ES. I tried to install the Eventgen and make it work, but it does not seem to be an easy procedure. Could you please provide me a straight forward solution.

0 Karma
Get Updates on the Splunk Community!

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...