Explore the Enterprise Security Content Updates app - Splunk...Explore the Enterprise Security...

3
Explore the Enterprise Security Content Updates app 1. Navigate to the ‘Content Library’ from the navigation bar. This is typically the landing page. 2. Ensure ‘Analytic Stories Stats’ tab is selected. 3. Review the contents to identify coverage for various security frameworks. 4. Scroll down to view a listing of the Analytic Stories. 5. Select the ‘Search Summary’ tab. 6. Review the various searches and details.

Transcript of Explore the Enterprise Security Content Updates app - Splunk...Explore the Enterprise Security...

Page 1: Explore the Enterprise Security Content Updates app - Splunk...Explore the Enterprise Security Content Updates app 1. Navigate to the ‘Content Library’ from the navigation bar.

ExploretheEnterpriseSecurityContentUpdatesapp

1. Navigatetothe‘ContentLibrary’fromthenavigationbar.Thisistypicallythelandingpage.

2. Ensure‘AnalyticStoriesStats’tabisselected.

3. Reviewthecontentstoidentifycoverageforvarioussecurityframeworks.

4. ScrolldowntoviewalistingoftheAnalyticStories.5. Selectthe‘SearchSummary’tab.6. Reviewthevarioussearchesanddetails.

Page 2: Explore the Enterprise Security Content Updates app - Splunk...Explore the Enterprise Security Content Updates app 1. Navigate to the ‘Content Library’ from the navigation bar.

ExploretheAnalyticStories

1. Navigatetothe‘AnalyticStoryDetail’pagefromthenavigationbar.

2. SelectanAnalyticStoryfromthedropdown .

3. ReviewthevarioussearchesthatmakeuptheAnalyticStory3.1. Detectionsearches,contextualsearches,and

investigativesearches

Page 3: Explore the Enterprise Security Content Updates app - Splunk...Explore the Enterprise Security Content Updates app 1. Navigate to the ‘Content Library’ from the navigation bar.

Enableandcustomizeasearch

1. GototheEnterpriseSecurityapp2. NavigatetoConfiguration->ContentManagement3. Inthe‘App’dropdown,selectDA-ESS-ContentUpdate4. Inthe‘Type’dropdown,selectCorrelationSearch

5. Selectthesearch‘ClientsConnectingtoMultipleDNSServers’

6. EditthesearchtoalertwhenthenumberofdifferentDNSserverscontactedis>7

7. ClickSave