Accept License Agreements

Thank You

Downloading Splunk ES Content Update
SHA256 checksum (splunk-es-content-update_1013.tgz) c08034d05c645fb805ae005761e3c002a31bfea512504282d9cf4eb1a8225682
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

Splunk ES Content Update

Splunk Built
This subscription service delivers pre-packaged Security Content for use with Splunk Enterprise Security. Subscribers get regular updates to help security practitioners more quickly address ongoing and time-sensitive customer problems and threats.

Requires Splunk Enterprise Security version 4.5 or greater.

For more information please visit the Splunk ES Content Update user documentation.

Release Notes

Version 1.0.13
April 11, 2018

Splunk ES Content Updates 1.0.13 Copyright (C) 2018 Splunk Inc. All rights reserved.

New Analytic Stories:
Cloud Security:
-- Unusual AWS EC2 Modifications - Monitor your AWS environment for new or modified instances created by users who have not previously performed these actions. In some cases, these behaviors may indicate that your environment has been compromised.

-- Disabling Security Tools - Attackers may modify or disable security tools in their efforts to avoid detection and operate without barriers. This Analytic Story allows you to monitor your endpoints for someone disabling your security tools.

Updated Analytic Stories:
-- DHS Report TA18-074A - Added detection searches to monitor for new administrator accounts and outbound SMB network connection.

Cloud Security:
-- AWS User Monitoring - Added searches to detect when a previously unseen user creates an EC2 instance.

For more please see the user documentation:


Subscribe Share

Splunk Certification Program

Splunk's App Certification program uses a specific set of criteria to evaluate the level of quality, usability and security your app offers to its users. In addition, we evaluate the documentation and support you offer to your app's users.

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 50GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
© 2005-2018 Splunk Inc. All rights reserved.
Splunk®, Splunk>®, Listen to Your Data®, The Engine for Machine Data®, Hunk®, Splunk Cloud™, Splunk Light™, SPL™ and Splunk MINT™ are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners.