Checklist for the Splunk Enterprise Security Notable Event Ingestion integration

Use this checklist to guide you through all the tasks of the integration. The following checklist includes setup and installation tasks and examples of use cases that include expected results for the integration.

Before you begin

Roles required: sn_si.ingestion_profile_admin, admin, sn_si.admin, sn_si.analyst, Splunk Enterprise Security administrator

Note: Users with the sn_si.admin role can perform all operations available to a profile admin, as the sn_si.admin role inherits the required permissions by default.

About this task

Track your progress with the setup, installation, and configuration of the integration with the following table. Complete all the tasks for a step before moving on to the next step. Each row of the table lists tasks and identifies the roles that are required to perform the tasks. Numbered topics of the installation and configuration guide are also referenced.

Roles required for each task are listed with each step in the following table.

Procedure

  1. Track your progress with the setup, installation, and configuration of the integration.
    Complete all the tasks for a step before moving on to the next step.
  2. Follow the steps in the table in the order that they are presented.
    You have successfully completed the set up steps and verified expected results for the integration.