Splunk Search

Should I hide Extreme Search?

daniel333
Builder

All,

I just installed ES. We're moving nice and slow here. I see it installs a supporting app called "Extreme" Search. Is there any reason to leave this isVisible=true? Should I just hide it from the menu's or is this something eventually users really get into?

0 Karma

jcoates
Communicator

Hi,

Extreme Search is used to help you answer qualitative questions like "is the amount of critical malware normal?" George Starcher wrote an excellent introduction to it here: http://www.georgestarcher.com/splunk-getting-extreme-part-one/

The version in Enterprise Security is pretty old, and IIRC the visualizations it ships are broken; you might want to download this to get a better feel for what it can do: https://splunkbase.splunk.com/app/2855/#/details

At the end of the day, it's step one in a sequence... see https://www.scianta.com/xvcs for the latest tech.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...