You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
|
|
1 year ago | |
|---|---|---|
| .. | ||
| bin | 1 year ago | |
| default | 1 year ago | |
| local | 1 year ago | |
| metadata | 1 year ago | |
| static | 1 year ago | |
| README | 1 year ago | |
| splunkbase.manifest | 1 year ago | |
README
Enterprise Security Configuration Explorer
by Dennis Morton
-------------------------------------------
The purpose of this App is to make it simpler to explore your ES knowledge objects and get an overview of how things are configured. For example:
* Which Correlation Searches are enabled, real-time, or use MLTK?
* How many and which Key Indicators are accelerated?
* Which searches set risk scores and by how much?
* Who made changes to Correlation Searches?
* ... and much more.
I've been using versions of this App for quite some time because it scratched an itch ;-)
Requirements: Enterprise Security >= 6.0 since this is the version that replaced Extreme Search with MLTK.