Security

Security
Community Activity
karu0711
Data field  "FW: [ DOC 45 ] DTP: DEMO XXX CCC | 20147" from this I need to extract  "DEMO XXX CCC"output subject fiel...
by karu0711 Communicator in Security 03-28-2023
0 4
0
4
crsplunkr
looking for the best way to audit all users accessing REST endpoints found a way to list users, but any way to limit ...
by crsplunkr Loves-to-Learn Everything in Security 03-24-2023
0 1
0
1
Burndata
Hello, I have some log messages like this, where various info is delimited by double-colons: {"@message":"[\"ERROR ::...
by Burndata Explorer in Security 03-24-2023
0 2
0
2
keio_splunk
Splunk web is returning HTTP 500 internal server error after entering login credential as splunkd fails to start up. ...
by keio_splunk Splunk Employee Splunk Employee in Security 03-23-2023
0 2
0
2
karu0711
I want to extract 5degit. number 54879 as number field  
by karu0711 Communicator in Security 03-23-2023
0 4
0
4
syadavsplunk
Hi Splunk Experts I have a set of set of users whom I just want them to allow only run ad-hoc searches. I don't want ...
by syadavsplunk Observer in Security 03-22-2023
0 4
0
4
jamie1
Hi There,I am new to Splunk and have data coming in from just one server. I have tried running the basic brute force ...
by jamie1 Communicator in Security 03-22-2023
0 1
0
1
naveenSharma
I am trying to send data from salesforce to Splunk using Http POST method but am getting error saying invalid certifi...
by naveenSharma New Member in Security 03-22-2023
0 0
0
0
karu0711
FW: [ DOC 45 ] DTP: DEMO XXX CCC | 20147I want to extract number after pie as field name "data".  what is the regex?
by karu0711 Communicator in Security 03-21-2023
0 5
0
5
splunker1981
Hi fellow Splunkers, I'm wondering is someone can tell me how to share a custom command stored within a custom App g...
by splunker1981 Path Finder in Security 03-21-2023
0 2
0
2
maurobissante
Hello!  One of our customer has a problem with this executable "C:\Program Files\SplunkUniversalForwarder_script\file...
by maurobissante Explorer in Security 03-15-2023
0 1
0
1
im_bharath
Hello everyone,  i have this below SPL i am using,  index=abcde* | eval logtype = if(match(_raw,".*?LTStamp.*?ConnID....
by im_bharath Path Finder in Security 03-14-2023
0 7
0
7
dasveruckte
Does anyone know why I would be getting very bad browsing performance when searching through large events regardless ...
by dasveruckte New Member in Security 03-08-2023
0 1
0
1
DG
Dear Community,We know that there are several options to mask sensitive data before/during ingestion. But generally, ...
by DG Explorer in Security 03-07-2023
0 0
0
0
splunkis0927
root@ubuntu-linux-22-04-desktop:/opt/splunk/bin# uname -aLinux ubuntu-linux-22-04-desktop 5.15.0-48-generic #54-Ubunt...
by splunkis0927 Engager in Security 03-06-2023
0 5
0
5
nick405060
Question says it all. I had pseudo-accomplished this for my users for the last 18 months by removing access to the se...
by nick405060 Motivator in Security 03-01-2023
3 5
3
5
matt8679
Prior to upgrading to Splunk Enterprise 9.0 (we were on 8.2.6), when creating or editing a role, the indexes tab had ...
by matt8679 Path Finder in Security 02-26-2023
0 5
0
5
juniormint
I was looking at the list of capabilities and it was not clear to me which would grant the ability to create new inde...
by juniormint Communicator in Security 02-26-2023
0 6
0
6
jawaj30860
I have configured SAML 2.0 SSO with our own IdP. My local splunk app http://khal:8000/ successfully redirect to Asser...
by jawaj30860 New Member in Security 02-23-2023
0 7
0
7
LionWolf
0
2
qcjacobo2577
I am attempting to set up encryption between a Splunk Universal Forwarder (verion 9.0.3) and a Splunk Heavy Forwarder...
by qcjacobo2577 Path Finder in Security 02-17-2023
0 2
0
2
verbal_666
It's making me crazy!!! Splunk Enterprise 8.2.6, Cluster SH with 3 members.     [role_test] cumulativeRTSrchJobs...
by verbal_666 Builder in Security 02-15-2023
0 1
0
1
chimell
How can I created dashboard for my entities like image belong in IT Essentials work app. I download the manuel named:...
by chimell Motivator in Security 02-15-2023
0 0
0
0
YanivWiz
Hi   Is there an option to add MFA to my Splunk Base account where I upload new apps and versions?
by YanivWiz New Member in Security 02-14-2023
0 2
0
2
khusain_splunk
We have a distributed Splunk environment and the certificate for Splunk API in port tcp/8089 on the search head has e...
by khusain_splunk Splunk Employee Splunk Employee in Security 02-13-2023
0 7
0
7
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...