What's new in Splunk Security Essentials
The security content delivery endpoint for Splunk Enterprise Security Content Update (ESCU) has been updated to comply with Splunk guidance. If you are using Splunk Security Essentials version 3.7.1 or lower, the last supported ESCU version is 4.22.0. In order to get the latest ESCU version, upgrade Splunk Security Essentials to version 3.8.0. For more information, see What's new in 3.8.0.
This release of Splunk Security Essentials includes the following enhancements.
What's new in 3.4.0
This release of Splunk Security Essentials includes the following enhancements:
New Feature or Enhancement | Description |
---|---|
MITRE ATT&CK Framework dashboard enhancements |
See The MITRE ATT&CK Framework Dashboard in the Use Splunk Security Essentials manual. |
Custom content cards are automatically created | The correlation searches in your environment are now automatically imported into Splunk Security Essentials as custom content. This means you will see your content on the MITRE ATT&CK Matrix in the Analytic Advisor with minimum input. See Track active content in Splunk Security Essentials using content introspection in the Use Splunk Security Essentials manual. |
Correlation searches mapped to custom content in Splunk Security Essentials update automatically | Every five minutes, Splunk Security Essentials checks for changes to the description, search string, or annotations in Splunk Enterprise Security and automatically makes those updates in Splunk Security Essentials. |
New default products are detected when you run Data Inventory | There is now better support for Salesforce, Zscaler, Orca, Dtex, Zeek, various Azure, Google, and AWS data sources, and many databases. |
Set Up menu | Use the new Set Up menu to review and complete the steps needed to set up Splunk Security Essentials. See Configure Splunk Security Essentials in the Use Splunk Security Essentials manual. |
Recommended add-ons | On the Security Content page, add-ons that you need to configure to make a detection work are now recommended and linked to from the detection. |
Known issues for Splunk Security Essentials |
This documentation applies to the following versions of Splunk® Security Essentials: 3.4.0
Feedback submitted, thanks!