Configure Splunk Enterprise Security to use the Machine Learning Toolkit

You can configure Splunk Enterprise Security (ES) to use the Machine Learning Toolkit (MLTK). MLTK enables users to create, validate, manage, and operationalize machine learning models through a guided user interface. See About the Machine Learning Toolkit in the Splunk Machine Learning Toolkit User Guide.

Using a version of ES that is 6.0.0 or higher

If you are using ES 6.0.0 or higher, MLTK is included in the installer. There are no additional steps. See Release Notes for Splunk Enterprise Security.

Using a version of ES that is lower than 6.0.0

If you are using a version of ES that is lower than 6.0.0, complete the following steps to configure ES to use MLTK.

After downloading MLTK from Splunkbase, visit this page for installation instructions, then follow the steps below to import MLTK for use with ES.

1. On the Enterprise Security toolbar, browse to Configure > General > App Imports Update

2. Edit the update_es input

3. In the field for "Application Regular Expression," add the following to the end of the existing string: |(Splunk_ML_Toolkit)

4. Click "Save"

Detailed documentation on importing an app/add-on can be found at https://docs.splunk.com/Documentation/ES/5.2.2/Install/ImportCustomApps#Import_add-ons_with_a_different_naming_convention

