Hi all,
Just installed splunk security essentials app and after that did a "Start Searches" , its running for long time.
Is there anything am missing here,
Am data inventory is not showing anything
No data sources as well.
Please guide me.
I have the same question ,can you share that how you solved it? please~
Splunk Security Essentials is a "how-to" app rather than a "plug-and-play" app. Think of it like a cookbook that tells you how to bake a cake, but does not actually bake cakes.
Review the SSE use cases and select those that might apply in your environment. Review the SPL and run the samples to see if any data is found. Bear in mind you probably will have to modify the searches as they often use "index=*" or expect sourcetypes you don't have.
Thank you so much and i can relate that now effectively.