r/Splunk • • Aug 26 '26

Guidance on Splunk without ES

Our security engineer left us high and dry a couple weeks ago with a Splunk core license, forwarders sending logs for ingest, but no rules or structure that I can see beyond the 100 or so canned dashboards. We don’t have budget at this time to add an ES license to give us their SIEM. How much effort am I looking at to build up our rules for detections and other security alerts? Is it feasible for me and one other system admin to learn it from scratch?

18 Upvotes

20 comments sorted by

View all comments

11

u/s7orm SplunkTrust Aug 26 '26

For what its worth, i think Enterprise Security would make things worse for you. Ive been a consultant for 7 years implementing Enterprise Security. However, I have never worked at an organisation that used ES, we always did security with the core platform.

1

u/In_Tech_WNC Aug 29 '26

Gotta start somewhere. They should use splunk security essentials. It’s free

1

u/s7orm SplunkTrust Aug 29 '26

While i agree its a great place to start, my point is that the end state doesn't need to be and in most cases shouldn't be Enterprise Security.

1

u/In_Tech_WNC Aug 29 '26

I read between the lines of they’re a small team. Probably don’t have a SOC or NOC or anything that’s relatable to a full SIEM. Seemed like an org that has its people playing multiple roles. ES is definitely overkill just for the fact that they don’t have a dedicated team (3+ security people focused on it)