Security

Security
Community Activity
phamxuantung
Hello,We just got our application pentest on Splunk, and there are many issues that pop up. These issues are:1. SQL I...
by phamxuantung Communicator in Security 07-28-2022
0 5
0
5
wiederkehrc
Hi, we're looking into bulding use case for hashicorp vault. We've had a brief look at their app that is mentioned he...
by wiederkehrc Explorer in Security 07-27-2022
0 0
0
0
mctester
I'm trying to automate the creation of an App using either the Remote CLI or the REST API. This involves creating an ...
by mctester Communicator in Security 07-26-2022
2 6
2
6
MathewRogers
Splunk support, I am working out an SSO solution with DOD CAC (certificate authentication). I am doing this through u...
by MathewRogers Explorer in Security 07-20-2022
1 3
1
3
premforsplunk
Hi Folks, Looking to setup a splunk cloud instance for my organization. Whether cloud version offers VPN connection...
by premforsplunk Explorer in Security 07-20-2022
0 6
0
6
afx
Hi, I am looking for real-time events from the aufit trail for capability assignments/changes, but it looks like thi...
by afx Contributor in Security 07-18-2022
0 4
0
4
waJesu
I am new to Splunk and need help directing estreamer logs to a particular directory in Splunk
by waJesu Path Finder in Security 07-14-2022
0 0
0
0
daniel333
Having trouble with my roles/groups mapping with SAML.Setting up Azure AD+SAML on a test host here and my claim for g...
by daniel333 Builder in Security 07-12-2022
0 0
0
0
julian0125
Hello friend, I've got the next issue trying to run ./splunk start or status. How can i fix it? i think it is a user ...
by julian0125 Explorer in Security 07-08-2022
0 11
0
11
yaarek
Hi,I'm trying to add splunk access to a user.I have a search which creates lookup with hosts names. It is created bas...
by yaarek New Member in Security 07-06-2022
0 0
0
0
rafiwicht
I reinstalled Splunk with clustering today. The problem is that I keep getting 'Signature mismatch between license sl...
by rafiwicht Explorer in Security 07-01-2022
0 8
0
8
mmoayed
Hi, I want to get back Token id from the Curl command below :curl -k -u UserName:Password -X POST https://0.0.0.0:808...
by mmoayed New Member in Security 07-01-2022
0 5
0
5
andrew_burnett
A lot of our Windows UF are getting this message in Windows Event Logs, "Splunk could not get the description for thi...
by andrew_burnett Path Finder in Security 06-30-2022
0 2
0
2
kenster89
To detect a failed login following by successful login (within a 60 second) period, I run: index=myindex sourcetype=w...
by kenster89 Engager in Security 06-30-2022
0 1
0
1
UnivLyon2
Hello, We use Splunk 6.2.0 and the server.pem certificate will be expired in 10 days: openssl x509 -in /opt/splunk/et...
by UnivLyon2 Explorer in Security 06-30-2022
0 25
0
25
IRHM73
Hi, I wonder whether someone may be able to help me please. I'm running the query below to obtain information about s...
by IRHM73 Motivator in Security 06-29-2022
0 6
0
6
weimsec
Hello!I am looking for a way to override the built-in Trigger Condition for Notable Response Actions, "For each resul...
by weimsec New Member in Security 06-29-2022
0 0
0
0
waJesu
I need help on how to create a WIDS/IDPS/Internet Content Filtering dashboard in Splunk so that I can continuously mo...
by waJesu Path Finder in Security 06-29-2022
0 2
0
2
Vicmeister
Hi, Security alert: Splunk Universal Forwarder. Is this a customer installable upgrade (to version 9), or do I need t...
by Vicmeister New Member in Security 06-29-2022
0 1
0
1
nanthakumarraja
In the context of connecting Splunk Cloud and Phantom. Does Phantom/Splunk SOAR support mTLS?
by nanthakumarraja New Member in Security 06-29-2022
0 0
0
0
Nilesh3110
I need to find out the list of users who did not login to splunk for more than 30 days. I need to know when the user ...
by Nilesh3110 Explorer in Security 06-29-2022
0 12
0
12
kkrises
Hello all, we're configuring Splunk Enterprise security app within our environment, while testing alerts  the alert a...
by kkrises Path Finder in Security 06-28-2022
0 3
0
3
danielteachesit
All, I've noticed by default that Splunk Forwarder gives itself /bin/bash  in /etc/passwd. e.g.splunk:x:1001:1001:Spl...
by danielteachesit New Member in Security 06-28-2022
0 3
0
3
dstrants
Hello team, we are looking for an incident management solution and wish to try out Splunk On Call but we were not abl...
by dstrants New Member in Security 06-24-2022
0 3
0
3
tincheng
Anyone know where I can request an annual application security assessment report for Splunk product? I am looking for...
by tincheng New Member in Security 06-22-2022
0 0
0
0
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...