Security

Security
Community Activity
karu0711
Data field  "FW: [ DOC 45 ] DTP: DEMO XXX CCC | 20147" from this I need to extract  "DEMO XXX CCC"output subject fiel...
by karu0711 Communicator in Security 03-28-2023
0 4
0
4
crsplunkr
looking for the best way to audit all users accessing REST endpoints found a way to list users, but any way to limit ...
by crsplunkr Loves-to-Learn Everything in Security 03-24-2023
0 1
0
1
Burndata
Hello, I have some log messages like this, where various info is delimited by double-colons: {"@message":"[\"ERROR ::...
by Burndata Explorer in Security 03-24-2023
0 2
0
2
keio_splunk
Splunk web is returning HTTP 500 internal server error after entering login credential as splunkd fails to start up. ...
by keio_splunk Splunk Employee Splunk Employee in Security 03-23-2023
0 2
0
2
karu0711
I want to extract 5degit. number 54879 as number field  
by karu0711 Communicator in Security 03-23-2023
0 4
0
4
syadavsplunk
Hi Splunk Experts I have a set of set of users whom I just want them to allow only run ad-hoc searches. I don't want ...
by syadavsplunk Observer in Security 03-22-2023
0 4
0
4
jamie1
Hi There,I am new to Splunk and have data coming in from just one server. I have tried running the basic brute force ...
by jamie1 Communicator in Security 03-22-2023
0 1
0
1
naveenSharma
I am trying to send data from salesforce to Splunk using Http POST method but am getting error saying invalid certifi...
by naveenSharma New Member in Security 03-22-2023
0 0
0
0
karu0711
FW: [ DOC 45 ] DTP: DEMO XXX CCC | 20147I want to extract number after pie as field name "data".  what is the regex?
by karu0711 Communicator in Security 03-21-2023
0 5
0
5
splunker1981
Hi fellow Splunkers, I'm wondering is someone can tell me how to share a custom command stored within a custom App g...
by splunker1981 Path Finder in Security 03-21-2023
0 2
0
2
maurobissante
Hello!  One of our customer has a problem with this executable "C:\Program Files\SplunkUniversalForwarder_script\file...
by maurobissante Explorer in Security 03-15-2023
0 1
0
1
im_bharath
Hello everyone,  i have this below SPL i am using,  index=abcde* | eval logtype = if(match(_raw,".*?LTStamp.*?ConnID....
by im_bharath Path Finder in Security 03-14-2023
0 7
0
7
dasveruckte
Does anyone know why I would be getting very bad browsing performance when searching through large events regardless ...
by dasveruckte New Member in Security 03-08-2023
0 1
0
1
DG
Dear Community,We know that there are several options to mask sensitive data before/during ingestion. But generally, ...
by DG Explorer in Security 03-07-2023
0 0
0
0
splunkis0927
root@ubuntu-linux-22-04-desktop:/opt/splunk/bin# uname -aLinux ubuntu-linux-22-04-desktop 5.15.0-48-generic #54-Ubunt...
by splunkis0927 Engager in Security 03-06-2023
0 5
0
5
nick405060
Question says it all. I had pseudo-accomplished this for my users for the last 18 months by removing access to the se...
by nick405060 Motivator in Security 03-01-2023
3 5
3
5
matt8679
Prior to upgrading to Splunk Enterprise 9.0 (we were on 8.2.6), when creating or editing a role, the indexes tab had ...
by matt8679 Path Finder in Security 02-26-2023
0 5
0
5
juniormint
I was looking at the list of capabilities and it was not clear to me which would grant the ability to create new inde...
by juniormint Communicator in Security 02-26-2023
0 6
0
6
jawaj30860
I have configured SAML 2.0 SSO with our own IdP. My local splunk app http://khal:8000/ successfully redirect to Asser...
by jawaj30860 New Member in Security 02-23-2023
0 7
0
7
LionWolf
0
2
qcjacobo2577
I am attempting to set up encryption between a Splunk Universal Forwarder (verion 9.0.3) and a Splunk Heavy Forwarder...
by qcjacobo2577 Path Finder in Security 02-17-2023
0 2
0
2
verbal_666
It's making me crazy!!! Splunk Enterprise 8.2.6, Cluster SH with 3 members.     [role_test] cumulativeRTSrchJobs...
by verbal_666 Builder in Security 02-15-2023
0 1
0
1
chimell
How can I created dashboard for my entities like image belong in IT Essentials work app. I download the manuel named:...
by chimell Motivator in Security 02-15-2023
0 0
0
0
YanivWiz
Hi   Is there an option to add MFA to my Splunk Base account where I upload new apps and versions?
by YanivWiz New Member in Security 02-14-2023
0 2
0
2
khusain_splunk
We have a distributed Splunk environment and the certificate for Splunk API in port tcp/8089 on the search head has e...
by khusain_splunk Splunk Employee Splunk Employee in Security 02-13-2023
0 7
0
7
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...