Splunk Security Content Update Setup
SkillSecurity"Use when the user asks to install, upgrade, review, or validate ESCU or Splunk security content. Render,
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Splunk Security Content Update Setup skill
What this skill tells your AI
The instructions your AI receives, as published by chambear2809/splunk-cisco-skills in skills/splunk-security-content-update-setup/SKILL.md and read by ahel’s review.
Prerequisites
| Tool or access | Purpose | Verify |
|---|---|---|
| Bash and Python 3 | Run bundled setup and validation helpers | bash --version && python3 --version |
| Required product/platform access | Inspect or configure the selected target | Complete the documented preflight |
| Credential files for live modes | Keep secrets out of chat | Verify paths only |
Workflow Overview
┌───────────┐ ┌───────────────┐ ┌───────────────┐ ┌─────────────────┐
│ Preflight │ → │ Render/review │ → │ Apply/handoff │ → │ Validate evidence │
└───────────┘ └───────────────┘ └───────────────┘ └─────────────────┘
When to Activate
- Install, upgrade, review, or validate ESCU or Splunk security content.
- Preview and review the splunk security content update setup workflow before any live apply phase.
- Diagnose failed prerequisites, generated assets, configuration, or validation evidence.
Scope
Follow the documented read-only or render-first path whenever it is available. This skill does not imply permission to mutate live systems. Require explicit apply flags, protected credentials, and operator review for state changes.
Examples
Inspect the supported setup modes before selecting one:
bash skills/splunk-security-content-update-setup/scripts/setup.sh --help
Expected output: usage, supported modes, and required arguments are displayed without changing the target environment.
Inspect validation modes before running completion checks:
bash skills/splunk-security-content-update-setup/scripts/validate.sh --help
Expected output: offline, live, and completion options are displayed when the skill supports them; help exits without mutation.
Troubleshooting
| Issue | Cause | Resolution |
|---|---|---|
| Preflight fails | A required tool or access path is missing | Resolve it before rendering or applying |
| Rendered assets are incomplete | Required non-secret inputs are absent | Complete intake and render again |
| Apply is blocked | Review, credentials, or explicit acceptance is missing | Use the documented handoff |
| Validation is incomplete | Live evidence is unavailable | Record the gap and keep completion open |
Shared add-on completion gate
Whenever this workflow installs, configures, or hands off ESCU, follow the shared completion gate. Package delivery alone is not success; validate content prerequisites, enabled searches, and shipped views against data.
Render-first workflow for DA-ESS-ContentUpdate (ESCU). It produces a
reviewable install/upgrade plan, ES placement checks, analytic-story inventory
SPL, correlation-search activation review, and handoffs to ES configuration.
Its explicit --install and --all modes install the ESCU package; search
enablement and content mutation remain outside this skill.
Package Verification Boundary
The reviewed ESCU baseline is 6.4.0, the current public release, which
advertises Splunk 10.5. The package was downloaded, unpacked, and inspected
here, so the shared installer's default pin needs no review override. ESCU
ships new detections on every release, so always inventory the shipped
analytic stories and repeat the correlation-search activation review after an
upgrade — nothing here enables content for you.
Workflow
bash skills/splunk-security-content-update-setup/scripts/setup.sh --render \
--platform auto --es-app SplunkEnterpriseSecuritySuite
Execute
Preview the package-install plan:
bash skills/splunk-security-content-update-setup/scripts/setup.sh --all \
--dry-run --json
Install ESCU and run validation:
bash skills/splunk-security-content-update-setup/scripts/setup.sh --all --live
This installs the app package only. Correlation-search enablement and ES content
changes remain delegated to splunk-enterprise-security-config.
bash skills/splunk-security-content-update-setup/scripts/validate.sh \
--rendered-dir splunk-security-content-update-rendered --live
See reference.md for ESCU placement and activation-review guardrails.
Signals
- GitHub stars
- 37
- Forks
- 8
- Last commit
- Sep 2026
Advanced
- Catalog kind
- skill
- Gateway key
splunk-security-content-update-setup- Source
- github.com/chambear2809/splunk-cisco-skills