3
Explore the Enterprise Security Content Updates app 1. Navigate to the ‘Content Library’ from the navigation bar. This is typically the landing page. 2. Ensure ‘Analytic Stories Stats’ tab is selected. 3. Review the contents to identify coverage for various security frameworks. 4. Scroll down to view a listing of the Analytic Stories. 5. Select the ‘Search Summary’ tab. 6. Review the various searches and details.

Explore the Enterprise Security Content Updates app - Splunk...Explore the Enterprise Security Content Updates app 1. Navigate to the ‘Content Library’ from the navigation bar

  • Upload
    others

  • View
    10

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Explore the Enterprise Security Content Updates app - Splunk...Explore the Enterprise Security Content Updates app 1. Navigate to the ‘Content Library’ from the navigation bar

ExploretheEnterpriseSecurityContentUpdatesapp

1. Navigatetothe‘ContentLibrary’fromthenavigationbar.Thisistypicallythelandingpage.

2. Ensure‘AnalyticStoriesStats’tabisselected.

3. Reviewthecontentstoidentifycoverageforvarioussecurityframeworks.

4. ScrolldowntoviewalistingoftheAnalyticStories.5. Selectthe‘SearchSummary’tab.6. Reviewthevarioussearchesanddetails.

Page 2: Explore the Enterprise Security Content Updates app - Splunk...Explore the Enterprise Security Content Updates app 1. Navigate to the ‘Content Library’ from the navigation bar

ExploretheAnalyticStories

1. Navigatetothe‘AnalyticStoryDetail’pagefromthenavigationbar.

2. SelectanAnalyticStoryfromthedropdown .

3. ReviewthevarioussearchesthatmakeuptheAnalyticStory3.1. Detectionsearches,contextualsearches,and

investigativesearches

Page 3: Explore the Enterprise Security Content Updates app - Splunk...Explore the Enterprise Security Content Updates app 1. Navigate to the ‘Content Library’ from the navigation bar

Enableandcustomizeasearch

1. GototheEnterpriseSecurityapp2. NavigatetoConfiguration->ContentManagement3. Inthe‘App’dropdown,selectDA-ESS-ContentUpdate4. Inthe‘Type’dropdown,selectCorrelationSearch

5. Selectthesearch‘ClientsConnectingtoMultipleDNSServers’

6. EditthesearchtoalertwhenthenumberofdifferentDNSserverscontactedis>7

7. ClickSave