November 2018
Beginner
298 pages
7h 51m
English
Splunk Enterprise Security (ES) is an advanced analytics-driven security information and event management (SIEM) solution that can serve as the nerve center of a security ecosystem, giving teams the ability to discover, monitor, investigate, respond, and report on threats, attacks, and other abnormal activity found across the enterprise. It simplifies threat management, eases alert overload, and provides executives with a window into their business risks from security concerns.
Much like ITSI, ES continuously monitors the security-related data stored in Splunk Enterprise to visualize a security posture with dashboards that feature key security indicators that utilize static and dynamic thresholds and trending ...
Read now
Unlock full access