Share data in Splunk Enterprise Security
How data is collected
Splunk Enterprise Security uses saved searches to collect anonymous usage data. These searches run in the background regardless of whether or not you opt-in to send usage data to Splunk, and do not have any significant impact on performance.
What data is collected
Splunk Enterprise Security collects the following basic usage information:
Name | Description | Example |
---|---|---|
app.session.enterprise-security.drilldown-dashboard
| Reports on the telemetry for every notable event that is created such as the severity of the notable, the assets and identities that generated the notable, and so on. |
|
app.session.enterprise-security.risk-analysis-dashboard
| Reports on the usage of the Risk Timeline visualization on the Risk Analysis dashboard. |
|
app.session.enterprise-security.disposition-required
| Reports whether dispositions are required or not on Incident Review Settings page. |
|
app.session.enterprise-security.ir-event-timeline
| Reports the usage of the zoom in and zoom out functionality of the Event Timeline visualization on the Incident Review page. |
OR
|
app.session.enterprise-security.incident-review
|
|
|
app.session.enterprise-security.drilldown-search
|
|
|
app.session.enterprise-security.threat-topology
|
|
|
app.session.enterprise-security.mitre-matrix
|
|
|
app.session.enterprise-security.ba-enable-modal
|
|
|
app.SplunkEnterpriseSecuritySuite.active_users
| Report the number of active users. |
|
app.SplunkEnterpriseSecuritySuite.annotations_usage
| Report the number of users that enable and start using annotations in correlation searches for the risk framework. |
|
app.SplunkEnterpriseSecuritySuite.datamodel_distribution
| Performs a data model audit to determine which models are the most heavily used. |
|
app.SplunkEnterpriseSecuritySuite.feature_usage
|
|
|
app.SplunkEnterpriseSecuritySuite.datamodel_dataset_population
| Reports which sourcetypes are populating data models and data sets. |
|
app.SplunkEnterpriseSecuritySuite.identity_manager
| Reports statistics pertaining to the usage of the Assets and Identities Framework. |
|
app.SplunkEnterpriseSecuritySuite.investigation_information
| Report on the length of investigations in Splunk Enterprise Security. |
|
app.SplunkEnterpriseSecuritySuite.lookup_usage
| Reports statistics pertaining to the usage of the Asset & Identity Manager, such as lookup table size and number of entries. |
|
app.SplunkEnterpriseSecuritySuite.notable_event_status_changes
|
|
|
app.SplunkEnterpriseSecuritySuite.macro_usage
|
Reports on how users use ESCU output filers for their content. |
|
app.SplunkEnterpriseSecuritySuite.risk_event_information
|
|
|
app.SplunkEnterpriseSecuritySuite.risk_notable_information
|
|
|
app.SplunkEnterpriseSecuritySuite.ba_detections
|
|
|
app.SplunkEnterpriseSecuritySuite.ba_test_information
|
|
|
app.SplunkEnterpriseSecuritySuite.riskfactors_usage
| Reports how customers use the risk framework. |
|
app.SplunkEnterpriseSecuritySuite.risk_riskfactors_impact
| Reports how the customers engage with risk framework. |
|
app.SplunkEnterpriseSecuritySuite.saved_search_information
|
|
|
app.SplunkEnterpriseSecuritySuite.search_actions
| Reports what was searched for. |
|
app.SplunkEnterpriseSecuritySuite.search_execution
| Reports average run time by search to help gauge performance. |
|
data.context
| Reports how many times a given workbench panel was used and the distribution of fields drilled into from workflow actions. |
|
app.SplunkEnterpriseSecuritySuite.splunk_apps
| Reports what apps are installed along with Splunk Enterprise Security |
|
app.session.rum.measure
| Reports performance metrics around API calls. |
|