ESCU components
The ESCU app provides content in different configuration files that create a seamless working experience and helps to run the daily security operations in an organization.
The following configuration files are included in the default directory of the app:
- savedsearches.conf: The standard Splunk Platform configuration file that contains the search stanzas for detection analytics and various other metadata about a particular search. You can find detailed information on the ESCU savedsearches.conf configuration file on the security_content wiki page. For more information, see the Github link.
- analyticstories.conf: The standard Splunk Platform configuration file that contains stanza definitions and various other metadata about the analytic stories in the app. You can find detailed information on the ESCU savedsearches.conf configuration file on the security_content wiki page. For more information, see the Github link.
- macros.conf: The standard Splunk Platform configuration file that contains definitions of all the macros, which are used by the ESCU analytics. For more information, see the Github link
- transforms.conf: The standard Splunk Platform configuration file that contains lookup-related transform definitions, which are used by the ESCU analytics. For more information, see the Github link.
- collections.conf: The standard Splunk Platform configuration file that contains definitions for KV Store collections, which are used by the ESCU analytics. For more information, see the Github link.
Additionally, the following files are also included in the default directory of the app:
- Lookups: Directory that contains the latest lookups files (.csv), which are used by various detection analytics. For more information, see the Github link.
- 
Dashboards: Dashboard specific XML configurations for the various dashboards that are shipped in the ESCU app located in the following directory: default/data/ui/view
The following configuration files are deprecated:
- 
          analytic_stories.conf
- 
          use_case_library.conf
- 
          commands.conf