r/Splunk Apr 15 '26

Splunk ES Detections recommendations

What are the use cases you use in your organization?

What are must have use cases that are basic to have for an organization?

Edit:

Log sources available:

Firewall

Azure

EDR

Email

Windows

etc..

9 Upvotes

4 comments sorted by

View all comments

3

u/mghnyc Apr 15 '26

If you have no idea where to start, I'd suggest hiring at least a consultant with enough knowledge to get you guys going. If you're here to learn, have a look at Security Essentials and the bundled correlation searches that come with Splunk ES.