Splunk® Enterprise Security

Install and Upgrade Splunk Enterprise Security

This documentation does not apply to the most recent version of Splunk® Enterprise Security. For documentation on the most recent version, go to the latest release.

Configure and deploy Indexes

Splunk Enterprise Security uses a number of custom indexes for event storage. The indexes are defined in the indexes.conf file in the apps provided with Enterprise Security.

  • In a single server deployment, the installation of Enterprise Security creates the indexes in the default path for data storage. For an architectural overview, see "Single server deployments" in this manual.
  • In all other deployment types, the indexes must be created on all Splunk platform indexers or search peers. For an architectural overview, see "Distributed search deployments" in this manual.

Index configuration

The indexes defined in Enterprise Security do not provide configuration settings to address:

  • Multiple storage paths
  • Accelerated data models
  • Data Retention
  • Bucket sizing
  • Use of volume parameters.

For detailed examples of configuring indexes, see "indexes.conf.example" in the Splunk Enterprise Admin Manual.

Indexes by app

App context Indexes
DA-ESS-ThreatIntelligence ioc index is unused in this release.
threat_activity index contains threat list match events.
SA-AccessProtection access_summary
access_summary2
SA-AuditAndDataProtection audit_summary
audit_summary2
SA-EndpointProtection endpoint_summary
endpoint_summary2
SA-IdentityManagement session_start
session_end
SA-ThreatIntelligence notable index contains the notable events.
notable_summary index contains a stats summary of notable events used on select dashboards.
risk index contains the risk modifier events.
SA-NetworkProtection network_summary
network_summary2
network_summary3
traffic_center_summary
traffic_center_summary2
proxy_center_summary
proxy_center_summary2
whois
Splunk_SA_CIM cim_summary
Splunk_SA_ExtremeSearch xtreme_contexts

In addition, the add-ons might include custom indexes defined in an indexes.conf file.

Index deployment

Splunk Enterprise Security includes a tool to gather the indexes.conf and index-time props.conf and transforms.conf settings from all enabled apps and add-ons on the search head and assemble them into one add-on. For more details, see "Distributed Configuration Management" in this manual.

Last modified on 24 December, 2015
Install and deploy add-ons   Configure users and roles

This documentation applies to the following versions of Splunk® Enterprise Security: 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.5, 4.0.6


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters