Using Enterprise Security 8.0 workflows
You're new to Splunk Enterprise Security (ES) 8.0, and you're aware that in this version there are several changes to functionality compared to previous versions. You're looking for a quick intro to the key benefits and features in this new version.
Solution
This video shows you:
- How ES aligns with the Open Cybersecurity Schema Framework (OCSF)
- Changes to terminology, such as how notables are now referred to as findings
- How to work with new ES detection types: event-based detections, and findings-based detections
- How to use detection versioning
- How ES integrates with Splunk Mission Control
- How to generate finding groups
- How to work with response plans
- How to use integration with Splunk SOAR
Next steps
In addition, these resources might help you understand and implement this guidance:
- Splunk Docs: About Splunk Enterprise Security
- Product Tip: Installing and upgrading to Splunk Enterprise Security 8x
- Product Tip: Using risk-based alerting and detection in Enterprise Security 8.0
- Product Tip: Enabling auto-refresh on the Analyst queue in Enterprise Security
- Product Tip: Searching investigation artifacts with the Analyst queue in Enterprise Security 8.0