Splunk Search

Should I hide Extreme Search?

daniel333
Builder

All,

I just installed ES. We're moving nice and slow here. I see it installs a supporting app called "Extreme" Search. Is there any reason to leave this isVisible=true? Should I just hide it from the menu's or is this something eventually users really get into?

0 Karma

jcoates
Communicator

Hi,

Extreme Search is used to help you answer qualitative questions like "is the amount of critical malware normal?" George Starcher wrote an excellent introduction to it here: http://www.georgestarcher.com/splunk-getting-extreme-part-one/

The version in Enterprise Security is pretty old, and IIRC the visualizations it ships are broken; you might want to download this to get a better feel for what it can do: https://splunkbase.splunk.com/app/2855/#/details

At the end of the day, it's step one in a sequence... see https://www.scianta.com/xvcs for the latest tech.

Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...