Splunk Cloud Platform

SOC analyst wants single pane of glass into multi-instance Splunk Enterprise Security

splunkkrishdee
Explorer

Hello Splunkers

we have two instances of Splunk with ES (On Prem + Cloud)

how to pull all the notables from both the instances in to a single place?

i am going through the mothership and es mothership app in splunkbase

few clarification:

1. how ES mothership is depends on MOthership app. do we need to do the set up in mothership app which will communicates/send details to ES mothership app?

2. Where we need to install this app? seperate SH or in on prem sh or cloud?

 

3. what are the other alternative we hvae> can we try federated search for this. will it pull ES notable details?

 

Thanks

D

Labels (1)
0 Karma

splunkkrishdee
Explorer

Any update on this query?

0 Karma
Get Updates on the Splunk Community!

Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...