Security

Security
Community Activity
islam
Hi,i have indexed logs with epoc time format in the raw event like 1623070612620000000,and this time field is parsed ...
by islam Explorer in Security 06-10-2021
0 2
0
2
islam
Hi,how can we filter fortinet logs from splunk like informational data type, also can i filter fori logs comming from...
by islam Explorer in Security 06-10-2021
0 3
0
3
Nvijay92
Hello Everyone, We are having a situation on our Splunk system.We recently noticed that there are several Dashboards ...
by Nvijay92 Explorer in Security 06-10-2021
0 10
0
10
tilburn
Hi friends:Looking for some assistance from savvy folks with heavy forwarders / db_connect  / ssl experience. Environ...
by tilburn Observer in Security 06-10-2021
0 0
0
0
ollie920049
So far I've tried the built in roles User/Power/Admin, but only Administrator worked. I was wondering if anybody new...
by ollie920049 Path Finder in Security 06-09-2021
5 15
5
15
santosh121
Dear All,We are trying to build splunk cloud rest api call where we will be sending data from splunk cloud to another...
by santosh121 Explorer in Security 06-09-2021
0 1
0
1
hexx
I would like to set up my Splunk-to-Splunk (forwarder to indexer) connections to use SSL with common-name-based authe...
by hexx Splunk Employee Splunk Employee in Security 06-09-2021
24 14
24
14
SS1
Hi, i would like to give admin access to specific user 'Admin' access to specific app, how do i accomplish that?
by SS1 Path Finder in Security 06-08-2021
0 1
0
1
lilredcrawfish
Afternoon, I'm trying to format the date field for the malware data model.  Converting it from epoc.  But I dont know...
by lilredcrawfish Explorer in Security 06-08-2021
0 1
0
1
kamaljagga
Hello,I am trying to mask the password in the Windows event logs at index time but somehow my config is not working. ...
by kamaljagga Path Finder in Security 06-08-2021
0 11
0
11
aquinojason
Hi,Is there a way to limit or restrict the view of our custom "Navigation Menu" . Like we want to hide some reports f...
by aquinojason Path Finder in Security 06-03-2021
0 1
0
1
astatrial
Hi all,I have Splunk ES, with a bunch of rules.The issue is that correlation rules generate notables for each result,...
by astatrial Contributor in Security 05-31-2021
0 0
0
0
payl_chdhry
Hi All, We have a clustered environment where we want to enable and add HEC on Heavy Forwarder but I am not able to f...
by payl_chdhry Path Finder in Security 05-31-2021
0 2
0
2
kunou126
I am working on a proof of concept but I am failing to see where security comes in regarding forwarders and receivers...
by kunou126 Engager in Security 05-31-2021
1 3
1
3
SamHTexas
Reg. Ransomware. In addition to Security Essentials what other steps do I need to take to protect using Splunk. How d...
by SamHTexas Builder in Security 05-28-2021
0 0
0
0
splunkreal
Hello guys,is there documentation somewhere explaining roles of default certificates, especially cacert.pem/ca.pem :c...
by splunkreal Influencer in Security 05-28-2021
0 4
0
4
ebdavis
Quick details: We are running Splunk 6.4.2 on Windows 2k8 as a standalone deployment. We are using third part certs...
by ebdavis New Member in Security 05-28-2021
0 2
0
2
fazilhussain
Dear Friends. Please help me, I am new to Splunk. I cannot browse for More Apps. when i click on "Find more Apps"...
by fazilhussain Explorer in Security 05-25-2021
0 4
0
4
jaibalaraman
H Team I tried the below command , but the output is incorrect where all the count are showing under other instead . ...
by jaibalaraman Path Finder in Security 05-23-2021
0 1
0
1
gharri27
I have several groups with access to the same index. In authorize.conf these groups all either have access to wildcar...
by gharri27 New Member in Security 05-21-2021
0 0
0
0
dm1
Currently LDAP authentication is configured through an app on search heads and managed via deployment server. However...
by dm1 Contributor in Security 05-20-2021
0 0
0
0
agitelzon
I am trying to set up my forwarders to use SSL without having to use the built in client certs on version 8.0.2.1. It...
by agitelzon Explorer in Security 05-19-2021
0 1
0
1
jcorcoran508
Greetings:I inherited a splunk instance.   We use CyberArk to manage our passwords  Web GUI and CLI.  Here is my prob...
by jcorcoran508 Path Finder in Security 05-15-2021
0 1
0
1
garumuga
Hello Splunkers,Is there a way to restrict web-ui access ? Users shoud not be able to view any options/menus to choos...
by garumuga New Member in Security 05-14-2021
0 3
0
3
Nith1
Hi Can someone help me with the query for the below requirmenti have User A, User B, User C and so onn with the job s...
by Nith1 Path Finder in Security 05-13-2021
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...