Only the README.md file is in the app, but it lacks the detail about sourcetypes needed. For example, from Splunk Cloud: (Enterprise customers don't have access to this information and it's not in the README.md) kwagner001_1-1788481291088.png
... View more
Splunkbase doesn't have a link to the documentation for the newly update Cisco Enterprise Networking add-on and app. Specifically, we are looking for the sourcetypes supported, what data each sourcetype should include and source of the data (e.g. syslog, API/app calls, etc).
... View more
When using the Imperva Database Audit Analysis app (app number 3063), which DB Audit Policies should have their data sent to Splunk? The Database Connections Policy for sure (DB logins), but should things like the DDL or Database Configurations policies be sent as well? What about custom policies? Is there a standard set of Imperva DB Audit policies that should be used with Splunk Enterprise Security?
... View more