Security

Security
Community Activity
SplunkIT3337
I've searched the similar questions and did not find a direct answer. I have a Splunk APP (Code42) that fails becaus...
by SplunkIT3337 Explorer in Security 06-21-2023
2 10
2
10
AL3Z
Hi,I'm trying to exclude the service accounts of the users from the below event in splunk ES.<Event xmlns='http://sch...
by AL3Z Builder in Security 06-19-2023
0 3
0
3
GoliSH
Hi All,do you know if we can tell from Splunk what encryption protocols are used for NetScaler queries? There is no A...
by GoliSH Engager in Security 06-16-2023
0 0
0
0
Gursimar_singh
We have to update the certificates for secure communication between UF, HF and indexer. The way to prepare a combined...
by Gursimar_singh Engager in Security 06-13-2023
0 0
0
0
NK
WARNING: can't open config file: C:\\gitlab_runner\\builds\\build_home\\splunk/ssl/openssl.cnf So why is the default ...
by NK Path Finder in Security 06-09-2023
0 3
0
3
abi2023
I am try add to my notable event in correlation search next step analyst need to take. I am see some issue. when I li...
by abi2023 Path Finder in Security 06-07-2023
0 1
0
1
SecBit
Hi All, I would like to know what is the best way to simulate attacks within my organisation.  I cannot use Virtualbo...
by SecBit Observer in Security 06-06-2023
0 4
0
4
Quantum
Is there an easy way to tell what role a Splunk server is?
by Quantum Explorer in Security 06-06-2023
0 3
0
3
aberger0
Hello, Splunk published multiple vulnerabilities on June 1st. Reading through the documentation of every vulnerabilit...
by aberger0 Engager in Security 06-05-2023
0 3
0
3
KeithH
Hi. I am trying to run this in splunk cloud: |rest /services/search/jobs|search isRealTimeSearch=1 But getting this: ...
by KeithH Communicator in Security 06-01-2023
0 5
0
5
Quantum
  I have two machines one looks like it's a heavy forwarder, I can browse into the GUI of the first Splunk server but...
by Quantum Explorer in Security 05-30-2023
0 2
0
2
gwaters
Hello, I have a Splunk forwarder forwarding logs to a Splunk Server, and the SplunkServer is using a LetsEncrypt CA c...
by gwaters New Member in Security 05-30-2023
0 0
0
0
VijayA
Hi All, I request to help me with the steps to upgrade log4j to latest version in Splunk On-Prem distributed environm...
by VijayA Explorer in Security 05-28-2023
0 5
0
5
asmyth1995
HiI setup a Splunk Enterprise instance on a windows vm to collect active directory logs. I wanted to forward these lo...
by asmyth1995 Explorer in Security 05-24-2023
0 11
0
11
asmyth1995
Hi I setup a universal forwarder on a Windows VM to send Active Directory logs to the Splunk Cloud. I also want to se...
by asmyth1995 Explorer in Security 05-24-2023
0 9
0
9
MalcolmC
we had a vendor setup our Splunk instance and configure a "Brute Force Attack" alert with the following query. --- or...
by MalcolmC New Member in Security 05-22-2023
0 1
0
1
asmyth1995
0
1
chintu_jain
I am trying to setup Splunk forwarding using own certificates. Following is the configuration made. On Indexer (inpu...
by chintu_jain Explorer in Security 05-19-2023
0 4
0
4
AL3Z
Hello,I have a significant number of Notables raised by the Non-pdm alerts correlation search.The correlation search ...
by AL3Z Builder in Security 05-18-2023
0 1
0
1
calvinmcelroy
I am trying to work through an issue and cannot seem to find a answer. I need to create a bash script that uses an au...
by calvinmcelroy Path Finder in Security 05-17-2023
0 1
0
1
asmyth1995
Hi, I have been working on configuring a universal forwarder on a free Splunk Cloud trial. I have been using the the ...
by asmyth1995 Explorer in Security 05-16-2023
0 1
0
1
asmyth1995
Hi I have recently signed up to a free trial to use Splunk Cloud. When I accessed my instance it was asking for a use...
by asmyth1995 Explorer in Security 05-13-2023
0 1
0
1
gyilmaz
Hello, I need a Splunk ID for taking a Splunk Certification exam on PearsonVUE. How do I get the 6-digit ID?
by gyilmaz New Member in Security 05-11-2023
0 1
0
1
russell120k
When running splunk show deploy-poll or splunk set deploy-poll on the command line of a UF (Linux) I'm prompted to pr...
by russell120k Engager in Security 05-10-2023
0 1
0
1
Mikkyhack
Please how do i resolve this error  
by Mikkyhack Loves-to-Learn in Security 05-10-2023
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...