Splunk® Enterprise Security

Installation and Upgrade Manual

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

About Splunk Enterprise Security

Splunk Enterprise Security uses the Splunk platform's searching and reporting capabilities to provide the security practitioner with an overall view of their organization's security posture. Enterprise Security uses correlation searches to provide visibility into security-relevant threats and generate notable events for tracking identified threats. You can capture, monitor, and report on data from devices, systems, and applications across your environment.

If you purchase Splunk Enterprise Security, you can download the app from Splunkbase. Additionally, Splunk does not monitor data ingestion based on your license, irrespective of whether you are using the on-prem or the Cloud version. For example, if you purchase a 1 GB license for Splunk Enterprise and purchase another 1 GB for Splunk Enterprise Security app, you can ingest 2 GB of data, irrespective of the data set. Thus, you can monitor your own data ingestion and usage.

This manual is written for a user capable of installing, configuring, and administering Splunk software. If you need training on the Splunk platform and Enterprise Security, see Education Courses for Enterprise Security Customers.

Other manuals for Splunk Enterprise Security:

Last modified on 10 February, 2023
  NEXT
Share data in Splunk Enterprise Security

This documentation applies to the following versions of Splunk® Enterprise Security: 7.1.0


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters