Understand the data sources used in Splunk Security Essentials with the Data Source On-boarding Guides
Use the Data Source On-boarding Guides as a method to improve standardization in on-boarding data. The Data Source On-boarding Guides page includes a list of the Data Sources that are commonly used in Splunk Security Essentials, along with some of the common products for each. In this list, many of the products have guides that show you how to configure the products in your environment to send the logs required to fire security detections. To view these guides, follow these steps:
- In Splunk Security Essentials, navigate to Data > Data Source On-boarding Guides.
- Click the data source you are interested in to see more information and the associated guides.
Check data sources with the Data Source Check dashboard |
This documentation applies to the following versions of Splunk® Security Essentials: 3.3.0, 3.3.1, 3.3.2, 3.3.3, 3.3.4, 3.4.0, 3.5.0, 3.5.1, 3.6.0
Feedback submitted, thanks!