Just curious if there is any documentation to help understand the best practices to use Splunk Enterprise as a SIEM for Security Professionals / SOC analysts.
Or if anyone has any input, that would be appreciated as well.
I have been evaluating Splunk Security Essentials, which I've been using to create dashboards.
I guess the overall theme is whatever you do, do it with a plan.
I guess the overall theme is whatever you do, do it with a plan.
Lots of splunk searches, explanations, and mappings to MITRE ATT&CK here: https://splunkbase.splunk.com/app/3449/
the app is updated regularly by splunk's security research team.
Keep in mind that Splunk Enterprise Security and Splunk Security Essentials are two different things.
You might find some relevant information about best practices and use cases in the recordings of previous Splunk user conference sessions: https://conf.splunk.com/watch/conf-online.html?search=siem#/ .