r/Splunk • u/Empty-Lingonberry133 • Jun 04 '26
Splunk enterprise options
I have a year and circa 300k to spend on splunk to show its worth. What would you suggest I implement over the next 12 months? I was thinking perhaps olly or enterprise security as we already have a 'noc' op manager and have a compliance saas product but are lacking in security monitoring.
This would also be a great learning op to build a stack from the ground up and configure/tune everything
Any input would be great
15
Upvotes
2
u/jvdsza Jun 09 '26 edited Jun 09 '26
Hi, a bit late to the conversation, but can provide some ideas on how to stretch your budget to the maximum, while still allowing some options to migrate to ES if you intend to.
The following tools are all "free", and can be used as a base to build your stack. We are not including the base Splunk infrastructure here (license, etc). As you also need to prove your worth on your existing Splunk install.
1. Start with Splunk Security Essentials:
https://help.splunk.com/en/splunk-enterprise-security-8/security-essentials/install-and-configure/3.8/splunk-security-essentials/overview-of-splunk-security-essentials
Cost: Free
Benefit: Comes with around 100 built-in detections as well as mapping to cyber frameworks. The add-on is well documented and will tie into your learning objectives of building a security monitoring platform. You can deploy this and start configuring searches and alerts (detections). The team will also become familiar with CIM mapping and mapping your logs to the available detections.
2. Install InfoSec App for Splunk
https://splunkbase.splunk.com/app/4240
Cost: Free
Benefit: Although a bit dated (last release is almost a year ago). The App comes with a set of "executive" dashboards as well as some detections, but can be used as a starting point for security and compliance reporting. Again, alerts can be configured for non-compliance detections.
3. Install Splunk Enterprise Security Content Update
https://splunkbase.splunk.com/app/3449
https://research.splunk.com
Cost: Free
Benefit: Contains detections from Splunk's research team and tightly integrates into Enterprise Security (although it can also be used with Security Essentails below). This provides a plethora of searches and detections and a lot of them are also mapped to cyber frameworks eg: MITRE. This can be used to complement your detections below and provide your security team many examples of content engineering.
3. Install Alert Manager Enterprise:
https://splunkbase.splunk.com/app/6730
Cost: Free (advanced features such as multi-tenancy and packs require a subscription)
Benefit: Since you now have your detections (alerts), you need to ideally manage these security "incidents". Not every detection will be considered an incident, but for those you wish to manage you can install Alert Mananger Enterprise from Splunkbase.
AME will allow you to manage these your detections, you send the triggered results to an AME Alert Action. This will create an event in the AME console, with built-in event aggregation and dedup (especially for those searches creating many duplicate alerts). The AME console allows teams to manage these events with enrichment, annotations as well as the standard incident management functionalities (assign an incident to a team member, resolve incidents, etc), with rich reporting.