Transcript
Page 1: Explore the Enterprise Security Content Updates app - Splunk...Explore the Enterprise Security Content Updates app 1. Navigate to the ‘Content Library’ from the navigation bar

ExploretheEnterpriseSecurityContentUpdatesapp

1. Navigatetothe‘ContentLibrary’fromthenavigationbar.Thisistypicallythelandingpage.

2. Ensure‘AnalyticStoriesStats’tabisselected.

3. Reviewthecontentstoidentifycoverageforvarioussecurityframeworks.

4. ScrolldowntoviewalistingoftheAnalyticStories.5. Selectthe‘SearchSummary’tab.6. Reviewthevarioussearchesanddetails.

Page 2: Explore the Enterprise Security Content Updates app - Splunk...Explore the Enterprise Security Content Updates app 1. Navigate to the ‘Content Library’ from the navigation bar

ExploretheAnalyticStories

1. Navigatetothe‘AnalyticStoryDetail’pagefromthenavigationbar.

2. SelectanAnalyticStoryfromthedropdown .

3. ReviewthevarioussearchesthatmakeuptheAnalyticStory3.1. Detectionsearches,contextualsearches,and

investigativesearches

Page 3: Explore the Enterprise Security Content Updates app - Splunk...Explore the Enterprise Security Content Updates app 1. Navigate to the ‘Content Library’ from the navigation bar

Enableandcustomizeasearch

1. GototheEnterpriseSecurityapp2. NavigatetoConfiguration->ContentManagement3. Inthe‘App’dropdown,selectDA-ESS-ContentUpdate4. Inthe‘Type’dropdown,selectCorrelationSearch

5. Selectthesearch‘ClientsConnectingtoMultipleDNSServers’

6. EditthesearchtoalertwhenthenumberofdifferentDNSserverscontactedis>7

7. ClickSave


Recommended