Splunk Enterprise Security

biuld a siem without Enterprise security app

Depressedadmin
Explorer

Hi i'm going to build a minimal siem in our office and because of price can't get es app what I would like to know is what if i use security essential app with some third party like wazuh and make some correlation somehow,

could i detect threat and risks?

since i can't get answer any where else ,it would be great to help me 🙂

Labels (1)
Tags (1)
0 Karma

96nick
Communicator

Agree with @radam2000, the Infosec App for Splunk is a good entry way into SIEMing without the money of ES.

I'm on the same journey you are, and it isn't the easiest. I would use the following resources to get started:

  1. Infosec App for Splunk
  2. Splunk Security Essentials
  3. Data visualization apps for your logs (Windows Inf App, Unix App, FW app, etc.)

You mention using third party applications. You can definitely do that, just don't set up 20 tools that you need to look out for. It's fine not having the famous 'single pane of glass', but don't have too many tools going at once! 

Depressedadmin
Explorer

tnx you both for reply this is defiantly enlightening for me at this point

have you been heard about 'wazuh'? it mention itself as "Comprehensive SIEM "!

Depressedadmin
Explorer

OR since my main goal is to make siem to analyze my pentest  impacts or analyze attack simulations, is there other ways or even with similar applications?

tnx

0 Karma

radam2000
Path Finder

why don't you try the free InfoSec App... its also a good starting point and provides some pretty good information...

https://splunkbase.splunk.com/app/4240/

Rich

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...