Share data in Splunk Security Essentials
How data is collected
If you opt in globally on your Splunk Enterprise environment, Splunk Security Essentials activates an internal library to track basic usage and crash information. The library uses browser cookies to track unique visitors to the app, sessions, and sends events to Splunk using XHR in JSON format, with all user or system-identifying data resolved to GUIDs.
What data is collected
Splunk Security Essentials collects the following basic usage information:
Component | Description | Example |
---|---|---|
app.session.PageStatus
|
Reports that an example was opened. |
|
app.session.PageStatus
|
Reports that the SPL for an example was viewed. |
|
app.session.PageStatus
|
Reports that an alert was scheduled. |
|
app.session.PageStatus
|
Reports that an alert was scheduled. |
|
app.session.PageStatus
|
Reports that an onboarding guide was opened. |
|
app.session.PageStatus
|
Reports that filters were updated to filter for specific examples. |
|
app.session.PageStatus
|
Reports that from the home page, a use case was clicked on. |
|
app.session.BookmarkChange
|
Reports that an example was bookmarked. |
|
app.session.DataStatusChange
|
Reports that available data sources were either configured or introspected. |
|
app.session.CustomContentCreated
|
Reports that custom content was created. |
|
app.session.PageStatus
|
Reports that an error occurred. |
|
app.session.DataInventoryIntrospection
|
Reports when Data Inventory configuration started and when it finished. |
Starts
Ends
|
app.session.ManageBookmarks
|
Reports that a user navigated to the Manage Bookmarks page. |
|
app.session.PageStatus
|
Reports that a user opened a link that led to an external site, such as the Splunk documentation site. |
|