Managing content in Splunk Enterprise Security
As a Splunk Enterprise Security administrator, you can use the Content Management page to display, create, configure, and edit content that is unique to Splunk Enterprise Security, such as correlation searches, key indicators, saved searches, and swim lane searches.
- Create correlation searches in Splunk Enterprise Security
- Create and manage data models in Splunk Enterprise Security
- Create and manage key indicator searches in Splunk Enterprise Security
- Create and manage lookups in Splunk Enterprise Security
- Create and manage saved searches in Splunk Enterprise Security
- Create and manage search-driven lookups in Splunk Enterprise Security
- Create and manage swim lane searches in Splunk Enterprise Security
- Create and manage views in Splunk Enterprise Security
- Export content from Splunk Enterprise Security as an app
- Create and edit risk objects in Splunk Enterprise Security
Example: Add a generic intelligence source to Splunk Enterprise Security | Create and manage data models in Splunk Enterprise Security |
This documentation applies to the following versions of Splunk® Enterprise Security: 5.0.0, 5.0.1, 5.1.0, 5.1.1, 5.2.0, 5.2.1, 5.2.2, 5.3.0, 5.3.1, 6.0.0, 6.0.1, 6.0.2, 6.1.0, 6.1.1, 6.2.0, 6.3.0 Cloud only
Feedback submitted, thanks!