explore the enterprise security content updates app - splunk...explore the enterprise security...

3
Explore the Enterprise Security Content Updates app 1. Navigate to the ‘Content Library’ from the navigation bar. This is typically the landing page. 2. Ensure ‘Analytic Stories Stats’ tab is selected. 3. Review the contents to identify coverage for various security frameworks. 4. Scroll down to view a listing of the Analytic Stories. 5. Select the ‘Search Summary’ tab. 6. Review the various searches and details.

Upload: others

Post on 20-May-2020

10 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Explore the Enterprise Security Content Updates app - Splunk...Explore the Enterprise Security Content Updates app 1. Navigate to the ‘Content Library’ from the navigation bar

ExploretheEnterpriseSecurityContentUpdatesapp

1. Navigatetothe‘ContentLibrary’fromthenavigationbar.Thisistypicallythelandingpage.

2. Ensure‘AnalyticStoriesStats’tabisselected.

3. Reviewthecontentstoidentifycoverageforvarioussecurityframeworks.

4. ScrolldowntoviewalistingoftheAnalyticStories.5. Selectthe‘SearchSummary’tab.6. Reviewthevarioussearchesanddetails.

Page 2: Explore the Enterprise Security Content Updates app - Splunk...Explore the Enterprise Security Content Updates app 1. Navigate to the ‘Content Library’ from the navigation bar

ExploretheAnalyticStories

1. Navigatetothe‘AnalyticStoryDetail’pagefromthenavigationbar.

2. SelectanAnalyticStoryfromthedropdown .

3. ReviewthevarioussearchesthatmakeuptheAnalyticStory3.1. Detectionsearches,contextualsearches,and

investigativesearches

Page 3: Explore the Enterprise Security Content Updates app - Splunk...Explore the Enterprise Security Content Updates app 1. Navigate to the ‘Content Library’ from the navigation bar

Enableandcustomizeasearch

1. GototheEnterpriseSecurityapp2. NavigatetoConfiguration->ContentManagement3. Inthe‘App’dropdown,selectDA-ESS-ContentUpdate4. Inthe‘Type’dropdown,selectCorrelationSearch

5. Selectthesearch‘ClientsConnectingtoMultipleDNSServers’

6. EditthesearchtoalertwhenthenumberofdifferentDNSserverscontactedis>7

7. ClickSave