Cisco Security Suite 3.0.2 now includes Cisco IronPort Email Security Appliance (ESA) Data

Security Jason Conger

The Cisco Security Suite app continues to get updated for Splunk 6.x. The latest addition is support to Cisco IronPort Email Security Appliance (ESA). A new add-on has been published that provides Common Information Model compliant field extractions and tags for data from Cisco ESA. So now, the Cisco Security Suite supports:

Also, with each release, we incorporate more feedback about documentation. So, in addition to documentation found within the Cisco Security Suite app itself, a subset of “getting started” documentation has been published under the Documentation tab on http://apps.splunk.com/app/525/.

Stay tuned, there is more to come…

Related Articles

Splunk Enterprise Security Premier is Now Generally Available: Delivering the Industry’s Best Analyst Experience
Security
5 Minute Read

Splunk Enterprise Security Premier is Now Generally Available: Delivering the Industry’s Best Analyst Experience

Splunk is proud to announce the general availability of Splunk Enterprise Security (ES) Premier for cloud customers.
Threat Update: Industroyer2
Security
11 Minute Read

Threat Update: Industroyer2

The Splunk Threat Research Team offers an analysis of relevant detection opportunities of one of the new malicious payloads found by the Ukranian CERT named 'Industroyer2.'
ValleyRAT Insights: Tactics, Techniques, and Detection Methods
Security
12 Minute Read

ValleyRAT Insights: Tactics, Techniques, and Detection Methods

The Splunk Threat Research Team conducts an analysis for several variants of ValleyRAT’s malware samples to extract its MITRE ATT&CK tactics, techniques, and procedures (TTPs).