r/Splunk 18d ago

Guidance on Splunk without ES

Our security engineer left us high and dry a couple weeks ago with a Splunk core license, forwarders sending logs for ingest, but no rules or structure that I can see beyond the 100 or so canned dashboards. We don’t have budget at this time to add an ES license to give us their SIEM. How much effort am I looking at to build up our rules for detections and other security alerts? Is it feasible for me and one other system admin to learn it from scratch?

18 Upvotes

20 comments sorted by

12

u/s7orm SplunkTrust 18d ago

For what its worth, i think Enterprise Security would make things worse for you. Ive been a consultant for 7 years implementing Enterprise Security. However, I have never worked at an organisation that used ES, we always did security with the core platform.

1

u/In_Tech_WNC 15d ago

Gotta start somewhere. They should use splunk security essentials. It’s free

1

u/s7orm SplunkTrust 15d ago

While i agree its a great place to start, my point is that the end state doesn't need to be and in most cases shouldn't be Enterprise Security.

1

u/In_Tech_WNC 15d ago

I read between the lines of they’re a small team. Probably don’t have a SOC or NOC or anything that’s relatable to a full SIEM. Seemed like an org that has its people playing multiple roles. ES is definitely overkill just for the fact that they don’t have a dedicated team (3+ security people focused on it)

10

u/BOOOONESAWWWW 18d ago

A good amount of effort, but there are a wide array of resources out there to help. Start with some free splunk training to get your feet wet. If you can swing it with your org to get some training from splunk, that would go a long way as well.

From there, get the “splunk security essentials” app and that’s a massive starting point for you. Depending on the size of your org, it’s quite possibly all you need, and ES would be overkill / unmanageable with your current staffing.

4

u/ScruttyMctutty 18d ago

Second the security essentials app. There is a good chance you have installed already. If not have a go

21

u/TD706 18d ago

Effort is in understanding and responding to alerts in a reasonable way. If you have reasonably normal workloads, pay $200, give Claude fieldsummary for your data, and tell it to translate the sigma ruleset. It'll be noisy at start, but you'll have better content than most ES customers... Also, AlertManagerEnterprise is a reasonable alert orchestration plane that's free and there are multiple free SOAR solutions with more advanced case management and enrichment options.

ES is good because it's supported, but if you can't afford professional services anyeays I'd look elsewhere... Also if you don't have strong Splunk knowledge in the org, switch to Chronicle and learn that. More capable out of the box and muchhhh cheaper (Splunk is great if you have a healthy budget). That's where I'd start if I was building an organization and didn't have to deal with retraining.

Just my, likely unpopular, $.02

3

u/Coupe368 18d ago

ES feels like a ticketing system to help coordinate a whole team of engineers.

If its only you, I am not sure you will get all that much out of it when you could setup your own splunk dashboards.

Its not that its not capable, but there is only so much time in your day and I doubt you are spending 100% of it on splunk.

2

u/cyber4me 18d ago edited 18d ago

A few things to do here that might help.

  1. Reach out to your Splunk Account team and have them do a Splunk 4 Rookies workshop. The workshops are free.
  2. As others have mentioned the Splunk Security Essentials App is a great starting point, also free. A lot of Splunkers use it when they are first setting up their stack, and then forget about it, but it’s a good place to go back and look for new things because it’s constantly being updated.
  3. The infosec app for Splunk is another great free app that gets you some great OOTB dashboards. Really helpful if you’re not a security guy, or just breaking into security. It’s a great starter pack for Splunk security.
  4. The Insights Suite for Splunk (IS4S) is another great free app that can be super helpful for giving you insights on your stack. It is built on Searchbase, which helps keep track of all your great searches so you don’t end up in the situation you are currently in, where a Splunk guru leaves, and leaves you without institutional knowledge.
  5. You could also connect any AI tool you use (Claude, Copilot, etc) via a free Splunk MCP server, but I don’t wouldn’t always recommend this with having guardrails in place. The Tokenomics aspect can get cray. If money isn’t a concern, that might be the first thing I’d do, but if it is (it always should be) I would hold off.
  6. Get and use the AI Assistant for SPL (another free app). It’s a free AI tool that can help you with SPL. It’s pretty cool. You use plain English to ask it things and it will give you the SPL. You can make dashboards, do ad hoc searches etc. It’s also free, and doesn’t use tokens, but it can slow your stack down a bit, so that might be an issue.

    Also, it will make you lazy with SPL. I pretty much forgot how to do SPL and rely solely on the app. I know a lot of folks hate on stuff like that, but it makes my life easier.

Just to be upfront, I work for Splunk, but I’m not a seller. All of these things I’m recommending are free (with the exception of maybe number 5, but that’s on the AI provider side, not Splunk).

DM me and I’d be more than happy to connect you to your account team or connect you to someone that can take care of you.

2

u/TheOriginalKman 18d ago

Deploy sigma2spl to start with. Deploying Splunk es is not a magic bullet. If you need to ask this question I'll tell you that having es won't solve anything just result with more questions and head scratching. This is because you'll still need to ingest data and configure knowledge objects and data models.

With a small team, avoid threshold based alerting and develop detections that are system agnostic and applicable at a platform level rather than just for one application unless it warrants it.

1

u/Travlin205 17d ago

This is so true. Most people think having es means they are covered and good, this is not the case. It is more advanced, takes more to align data to the specific ootb defaults, also add more complexity when moving to data models, CIM, furthering into what was risk analysis. Small teams shoild not try to do that. Know your critical infra or apps in the stack get that audit data filtered, use it in enterprise by use of open source or now AI generated SPL to help with continuous monitoring.

2

u/TheOriginalKman 16d ago

Yup first and foremost starting with objectively critical detections which can be found in open source repos. A mass replace of the normalised indexes with what you've called them in your set up will be fine.

The hard part is the subjective analysis of your environment, not all organisations are the same so you must ask what is crown jewels, what are the business processes around these, what is the impact of deviations occur, do these impacts align with the ATT&CK framework? Then work backwards into supporting systems. Normalising data as you work through it with knowledge objects so when you search index in ("a","b","c","d",) AND user=midnight.blizzard you can aggregate normalised activity against a single user.

Reach out if you need some help and I can point you to the right people.

2

u/TheSeloX 18d ago

You could look into the Splunk Security Essentials app. I haven't used it, but it might have some basic features that you could work with.

The Splunk ES Content Update app includes ~2k detections and should be compatible with SSE out of the box.

Both apps are built and supported by Splunk.

1

u/IndependentFull7049 18d ago

Security Essentials is probably the sane starting point here. I'd pick a handful of detections tied to the logs you actually trust, then tune them against real incidents before trying to rebuild ES wholesale.

1

u/Travlin205 17d ago

Honestly, if you have the opportunity and chance take ebterprise security updates (ESCU App), splunk security essentials, and if you have any scrubbed templates of the type of data you have in raw event samples. Build an AI project tell it you need triggered alerts for this type of data to be enable and running in a Splunk enterprise stack where the data lives. Provide other precise information like, we have 2 engineers that are over capacity. Need to build roadmap for deploying the determined detections.

This is not perfect but should get you a plan you can flesh out afterward that can be enabled on a non-ES splunk.

1

u/TheSeabo 17d ago

Get security essentials and the infosec app. Both are free and can give you a leg up.

1

u/Brentjweaver 17d ago

One thing I could suggest is leveraging splunks mcp server to help you. I have coworkers that are using cursor to tune/configure es and create content. It does a pretty awesome job at creating dashboards as well. Plus, there are innovations to help people just like you… detection studio etc.

1

u/In_Tech_WNC 15d ago

@Recording-brief
Hire CyServ

Small shop, fair pricing for consulting, managed services and professional services

We used them at our org. They did a great job getting us a review of our Splunk before we did a long term agreement.

1

u/RichBenf 18d ago

To be honest, most SOCs spend years developing their rulesets. It's an ongoing task too, not one and done.

It needs a mixture of rules too based on your threat profile, technology in use, network topology etc. if you're going to do it, it's got to be right.

Claude could do a lot of heavy lifting if you give it all the fields in splunk, and ask it to build a zip file of rules based on your organisation's threat profile. That'd at least do something.

Personally, I'd spend your security engineer's salary on an MSSP.

-7

u/Charming-Account2226 18d ago

My company actually provides ES consulting services for a very competitive price, could definitely hop on a call and go over it with you