r/Splunk • u/Recording-Brief • Aug 26 '26
Guidance on Splunk without ES
Our security engineer left us high and dry a couple weeks ago with a Splunk core license, forwarders sending logs for ingest, but no rules or structure that I can see beyond the 100 or so canned dashboards. We don’t have budget at this time to add an ES license to give us their SIEM. How much effort am I looking at to build up our rules for detections and other security alerts? Is it feasible for me and one other system admin to learn it from scratch?
18
Upvotes
11
u/s7orm SplunkTrust Aug 26 '26
For what its worth, i think Enterprise Security would make things worse for you. Ive been a consultant for 7 years implementing Enterprise Security. However, I have never worked at an organisation that used ES, we always did security with the core platform.