- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk Es
revanthammineni
Path Finder
08-02-2021
01:33 PM
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

gcusello

SplunkTrust
08-03-2021
03:13 AM
Hi @revanthammineni,
the first thing you could do it's installing Enterprise Security Content Updates (ESCU) from Splunkbase (https://splunkbase.splunk.com/app/3449/) in this way you'll have up around 300 Use Case already available that you can enable if you have the related logs.
In addition I hint to follow the videos on YouTube and eventually to follow a training on ES Admin.
Ciao.
Giuseppe
