Splunk Search

Should I hide Extreme Search?

daniel333
Builder

All,

I just installed ES. We're moving nice and slow here. I see it installs a supporting app called "Extreme" Search. Is there any reason to leave this isVisible=true? Should I just hide it from the menu's or is this something eventually users really get into?

0 Karma

jcoates
Communicator

Hi,

Extreme Search is used to help you answer qualitative questions like "is the amount of critical malware normal?" George Starcher wrote an excellent introduction to it here: http://www.georgestarcher.com/splunk-getting-extreme-part-one/

The version in Enterprise Security is pretty old, and IIRC the visualizations it ships are broken; you might want to download this to get a better feel for what it can do: https://splunkbase.splunk.com/app/2855/#/details

At the end of the day, it's step one in a sequence... see https://www.scianta.com/xvcs for the latest tech.

Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...