Hi everyone, I'm trying to wrap my head around the best approach for threat hunting with Splunk at my company.
We have Splunk Enterprise running, and I see there's the full Enterprise Security (ES) suite. But I've also heard some folks just use the base platform with some specific security apps or custom searches.
For someone building out a threat hunting program, is ES genuinely worth the extra complexity and cost? Or can you get most of the way there with smart use of the base Splunk and some community add-ons? I'm curious about the real workflow differences.
Thanks in advance!
Still learning.
ES gives you a framework and a curated data model out of the box. It's a product built for a SOC. If you're a dedicated security team with the manpower to manage it, it structures the work for you.
But if you're asking this question, you probably aren't that team. The cost and complexity hit are real. You can absolutely build a capable hunting program on base Splunk. It just means you're building that framework yourself with saved searches, data model acceleration, and maybe a few solid apps. That's a lot of work, but it's often more flexible and you understand every piece of it. It comes down to whether you want to buy a finished house or pour the foundation and frame it yourself.
been there, migrated that