Splunk Search

Security Essentials- How to export rule list?

cybersej
Observer

H,

I want to take rules on security essentials as a list.I m try to search in app but I cant get rule list.There r many content in this app. https://docs.splunksecurityessentials.com/content-detail/ .I want to export this rule and colleration search as a xml.

Could u help me about this search?

 

Thanks.

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @cybersej,

I'm not sure that's possible to export all the rules in XML, but you could find all the Security Essentials rules at  https://docs.splunksecurityessentials.com/content-detail/ and all documentation at https://docs.splunksecurityessentials.com/ and https://docs.splunk.com/Documentation/SSE

Ciao.

Giuseppe

0 Karma

cybersej
Observer

Hi, I want to see in add-on. I need to table name correlation search update date and I need to sort by index that used in search.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @cybersej,

as I said, it isn't possible in an automatic way, only manually.

In addition, many searches contain macros and custom commands so it isn't so easy to read a search.

Some months ago, I had to build a group of searches for a customer that didn't want to pay for the ES, I analyzed with Security Essentials the available data and then I took one by one the possible searches.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...