Using Enterprise Security 8.0 workflows
You're new to Splunk Enterprise Security (ES) 8.0, and you're aware that in this version there are several changes to functionality compared to previous versions. You're looking for a quick intro to the key benefits and features in this new version.
How to use Splunk software for this use case
This video shows you:
- How ES aligns with the Open Cybersecurity Schema Framework (OCSF)
- Changes to terminology, such as how notables are now referred to as findings
- How to work with new ES detection types: event-based detections, and findings-based detections
- How to use detection versioning
- How ES integrates with Splunk Mission Control
- How to generate finding groups
- How to work with response plans
- How to use integration with Splunk SOAR
Next steps
In addition, these resources might help you understand and implement this guidance:
- Splunk Lantern Article: Installing and upgrading to Splunk Enterprise Security 8x
- Splunk Lantern Article: Using risk-based alerting and detection in Enterprise Security 8.0
- Splunk Lantern Article: Enabling auto-refresh on the Analyst queue in Enterprise Security
- Splunk Lantern Article: Searching investigation artifacts with the Analyst queue in Enterprise Security 8.0
- Splunk Resource: Cybersecurity Defense Analyst Learning Path

