Security

Security
Community Activity
aferone
I'd like to create a role in Splunk that gives access to one device's logs only instead of an entire index. Is thi...
by aferone Builder in Security 07-12-2011
1 2
1
2
maverick
wondering if Splunk https works with third-party wildcard certs. so far I got my Splunk indexer to start using my th...
by maverick Splunk Employee Splunk Employee in Security 07-06-2011
0 1
0
1
maverick
My understanding on the knowledge base article located here... http://www.splunk.com/base/Documentation/latest/Admin...
by maverick Splunk Employee Splunk Employee in Security 07-06-2011
0 1
0
1
thscheidegger
I'm trying to set up our infrastructure to use SSL encrypted connections. For this purpose I want to use existing sys...
by thscheidegger Explorer in Security 06-30-2011
3 2
3
2
infosec_skrc
Hello all, its told that the file in "c:/programfiles/splunk/etc/system/local/server.conf" in windows, has to be modi...
by infosec_skrc Explorer in Security 06-28-2011
0 5
0
5
stevengrigg
I just installed the current version of Splunk on my Fedora Core 14 laptop. There is an option at login for Splunk S...
by stevengrigg New Member in Security 06-27-2011
0 2
0
2
fman82
What is the full mechanism of the local Splunk authentication? What hashing algorithm does it use? Does it use a sal...
by fman82 Explorer in Security 06-24-2011
1 1
1
1
andrewkerr
Is it possible to limit a user to see and search logs from a certain list of hosts with only one index?
by andrewkerr Engager in Security 06-23-2011
1 1
1
1
Jason
We have a review process set up in Splunk where multiple end users log in and tag individual events. These tags MUST ...
by Jason Motivator in Security 06-21-2011
2 5
2
5
avlahutin
I have created a custom role that will serve as the admin role for a given application. For a dashboard object, I hav...
by avlahutin Explorer in Security 06-17-2011
0 12
0
12
joberget
Hi, I recently installed the new Splunk Universal Forwarder. I use the built-in bootup script that comes with Splunk,...
by joberget Path Finder in Security 06-15-2011
2 2
2
2
jstockamp
I've got about 5 searches that I want to be scheduled so that I can include them in a dashboard. I've set them all t...
by jstockamp Communicator in Security 06-15-2011
0 4
0
4
lisaac
I have to update the local file server.conf to allow only sslv3 on an indexer (4.1.3) due to a recent audit. There ar...
by lisaac Path Finder in Security 06-15-2011
3 2
3
2
pontifor
Hi this is a setup question for compliance monitoring. I have a linux box, so I index everything under /var/log. I ...
by pontifor New Member in Security 06-11-2011
0 1
0
1
gekoner
I have a very similar issues as MasterOogway mine is just on Windows. Running ver 4.1.6 I have a simple monitor set t...
by gekoner Communicator in Security 06-01-2011
1 5
1
5
vbumgarn
I have splunkd configured to run without ssl. It removes some hassle with self signed certificates, and eliminating ...
by vbumgarn Path Finder in Security 05-31-2011
4 7
4
7
fervin
Hello All, Has anyone figured out a good way to perform field extractions on the data contained in SEP firewall logs...
by fervin Path Finder in Security 05-31-2011
0 1
0
1
maverick
When using Certificate Authentication within Splunk, are they self-signed, or can I use third-party certs as well?
by maverick Splunk Employee Splunk Employee in Security 05-27-2011
1 1
1
1
MuS
Hi Splunk- and other Gurus Assumption: Captain Picard's room is a high security Environment, so him and only himsel...
by SplunkTrust SplunkTrust in Security 05-24-2011
15 3
15
3
tektsu
I am trying to install Splunk 4.2.1 on a CentOS 5 (64-bit) box. It starts with no problem, but when I try to connect ...
by tektsu New Member in Security 05-24-2011
0 3
0
3
EricPartington
I have set up LDAP access to the GC (3268) and it works great. However, i am now noticing that there is a lot of tra...
by EricPartington Communicator in Security 05-21-2011
1 2
1
2
Starlette
When I configure an allowed index for a role, and I choose Inheritance for another role. Users for this new roll dont...
by Starlette Contributor in Security 05-13-2011
0 1
0
1
matt
Since Splunk has a webserver how can I have it serve alternate HTML pages? I'd like to provide some simple instructi...
by matt Splunk Employee Splunk Employee in Security 05-12-2011
0 2
0
2
whitelord90
Hello, For some reason, splunkweb fails to start in first, my version is 4.2.1 any ideas where i can look for to ...
by whitelord90 Explorer in Security 05-08-2011
2 4
2
4
sideview
I'm encountering some difficulties trying to get setup.xml working reliably across multiple apps. When I take a ste...
by SplunkTrust SplunkTrust in Security 05-05-2011
2 4
2
4
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...