Share data usage in Splunk Enterprise Security
How data is collected
Splunk Enterprise Security uses saved searches to collect anonymous usage data. These searches run in the background regardless of whether or not you opt-in to send usage data to Splunk, and do not have any significant impact on performance.
Splunk Enterprise Security also uses FullStory to collect experiential user journey information with the user personally identifiable information redacted.
Splunk collects usage data to improve the design, usability, and experience of the product. Customers may opt-out of sharing AI data including, but not limited to, chats, responses, context, and feedback. To opt out of sharing this AI data, see Opt out of data sharing for the AI Assistant in Splunk Enterprise Security.
What data is collected
Splunk Enterprise Security version 8.3 collects the following basic usage information. This page includes new telemetry components introduced in version 8.3. Splunk Enterprise Security still collects components introduced in earlier versions. Use the version selector to see data collection documentation from earlier versions.
For more information on telemetry information collected by Splunk SOAR, see Share data from Splunk SOAR (Cloud).
| Component | Description | Example |
|---|---|---|
| app.UEBAContent.DeploymentInfo | General information about UEBA CMP deploument. |
|
| app.UEBAContent.SearchExecution | Information about UEBA Seraches execution times |
|
| app.UEBAContent.DetectionStatus | Metrics related to detection execution |
|
| app.UEBAContent.FailedSearches | Metrics related to failed UEBA seraches. |
|
| app.UEBAContent.SkippedSearches | Metrics related to skipped UEBA seraches. |
|
| app.UEBAContent.IndexStatsBySource | Index performance statistics. |
|
| app.UEBAContent.KvStats | Performance statistcs related to KV Store collections. |
|
| app.UEBAContent.IndexStats | Index performance statistics. |
|
| app.UEBAContent.DataAvailability | Information on data availability for UEBA detections. |
|
Mission control - bulkUpdateSuccess | A successful bulk update request in the Analyst Queue. |
|
Mission control - bulkUpdateGlobalSelectionFailed | A failed bulk update request when global selection is active (all items are selected across the entire queue). |
|
Enterprise security - aq-global-selection-active | Whenever a user clicks the "Select all X findings and investigations" button in the Analyst Queue to active global selection. |
|
Enterprise security - aq-assign-to-me-success | A successful request to "Assign to me" in the Analyst Queue. |
|
Enterprise security - aq-assign-to-me-failed | A failed request to "Assign to me" in the Analyst queue. |
|
Enterprise security - aq-global-assign-to-me-failed | A failed request to "Assign to me" when global selection is active in the Analyst Queue. |
|
|
Mission Control - | Successful pinning of a field in AQ Sidepanel. |
|
|
Mission Control - | Successful unpinning of a field in AQ Sidepanel. |
|
|
Mission Control - | Successful reordering of a pinned field in AQ Sidepanel. |
|
|
Mission Control - | Successful pinning of a field in Investigation Overview. |
|
|
Mission Control - | Successful unpinning of a field in Investigation Overview. |
|
|
Mission Control - | Successful reordering of a pinned field in Investigation Overview. |
|
|
Mission Control - | Successful pinning of a field in Investigation Overview Sidepanel. |
|
Enterprise security - aq-analyst-workflow | Sort AQ table by Entity name. |
|
Enterprise security - aq-analyst-workflow | Sort AQ table by Entity risk score. |
|
Enterprise security - aq-analyst-workflow | Sort AQ table by Finding score. |
|
Enterprise security - aq-analyst-workflow | View all nested findings/ finding groups in AQ table item. |
|
Mission Control - SIDEPANEL_INCLUDED_FINDINGS_TABLE | View all nested findings/ finding groups in AQ Sidepanel. |
|
Mission Control - SIDEPANEL_INCLUDED_FINDINGS_TABLE | View all nested findings when a finding group is expanded under Included Findings Table in AQ Sidepanel. |
|
Mission Control - SIDEPANEL_DETAILS_BREADCRUMBS | Ability to navigate using breadcrumbs at the top of AQ Sidepanel. |
|
Mission Control - FINDINGS_SIDE_PANEL | Show more findings/ finding groups in the findings side panel of Investigation Overview. |
|
Mission Control - FINDINGS_SIDE_PANEL | Show more findings within a finding group in the findings side panel of Investigation Overview. |
|
Mission Control - NESTED_DRILLDOWN_VIEW | Show the viewing duration on the nested drilldown view. |
|
Mission Control - NESTED_DRILLDOWN_VIEW | Show the action performed in the nested drilldown view. |
|
|
Mission Control -
| Show the associated findings checkbox is checked or not. |
|
Enterprise security - legacy-investigation-list | Legacy investigation list has been loaded. |
|
Enterprise security - legacy-investigation | Legacy investigation has been loaded. |
|
Enterprise security - select-add-app-to-versioning | On Configure → General Settings → Versioning, emits event when an app is selected. |
|
Enterprise security - confirm-add-app-to-versioning | On Configure → General Settings → Versioning, emits event when the confirm button is clicked on add apps. |
|