Splunk Search

Security Essentials- How to export rule list?

cybersej
Observer

H,

I want to take rules on security essentials as a list.I m try to search in app but I cant get rule list.There r many content in this app. https://docs.splunksecurityessentials.com/content-detail/ .I want to export this rule and colleration search as a xml.

Could u help me about this search?

 

Thanks.

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @cybersej,

I'm not sure that's possible to export all the rules in XML, but you could find all the Security Essentials rules at  https://docs.splunksecurityessentials.com/content-detail/ and all documentation at https://docs.splunksecurityessentials.com/ and https://docs.splunk.com/Documentation/SSE

Ciao.

Giuseppe

0 Karma

cybersej
Observer

Hi, I want to see in add-on. I need to table name correlation search update date and I need to sort by index that used in search.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @cybersej,

as I said, it isn't possible in an automatic way, only manually.

In addition, many searches contain macros and custom commands so it isn't so easy to read a search.

Some months ago, I had to build a group of searches for a customer that didn't want to pay for the ES, I analyzed with Security Essentials the available data and then I took one by one the possible searches.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...