Security

Security
Community Activity
twinspop
We are planning to move to SAML SSO soon. One of the drawbacks of SAML is that you cannot authenticate on the API any...
by twinspop Influencer in Security 07-20-2020
0 3
0
3
nikhils5501
I am trying to setup Gsuite SAML for Splunk. I followed the steps mentioned in this link:  https://clevertap.com/blog...
by nikhils5501 Loves-to-Learn Lots in Security 07-20-2020
0 2
0
2
Thundercat
Hi All,Thanks for taking the time to review this message.I attempting to create a Splunk notable that will allow me t...
by Thundercat Engager in Security 07-16-2020
0 2
0
2
muebel
When I look in the deploymentserver web interface, I see some Deployment Clients listed that I want to remove. Is it ...
by SplunkTrust SplunkTrust in Security 07-14-2020
0 2
0
2
sa20089562
Hi All, How would capture the netflows from different switces in different network zones.  I have deployed Independen...
by sa20089562 New Member in Security 07-11-2020
0 1
0
1
splunkceh
I am an admin user in the Splunk console on prem, and I was going to update the roles of certain admin users from adm...
by splunkceh Engager in Security 07-10-2020
0 2
0
2
TechSec
I've found that for Splunk Enterprise, there is the Securing Splunk Enterprise document, outlining recommended securi...
by TechSec Engager in Security 07-10-2020
0 2
0
2
chris94089
Greetings,I'm setting up an alert and I noticed that for each alert trigger, only 1 of each trigger type is allowed. ...
by chris94089 Path Finder in Security 07-09-2020
0 1
0
1
ephrem3232
Splunk Query for adding a column for ISP of blocked IP address?  Thank you,
by ephrem3232 Explorer in Security 07-06-2020
0 5
0
5
judyhuang
We are running Splunk Version 6.3 and are using LDAP to manage authentication. We need to run "auth reload" after ne...
by judyhuang Explorer in Security 07-03-2020
0 7
0
7
a_kearney
Following the best practices for removing an LDAP user I am at the stage where I want to remove  the $HOME/splunk/etc...
by a_kearney Path Finder in Security 06-30-2020
0 0
0
0
sylim_splunk
We see inconsistent response in the UI (settings --> Users and Authentication --> access control --> users). Some use...
by sylim_splunk Splunk Employee Splunk Employee in Security 06-29-2020
0 1
0
1
mailmetoramu
Hello All,We do have an centralized syslog receiver named "spl-fwdser" which receives the logs from various devices a...
by mailmetoramu Explorer in Security 06-29-2020
0 1
0
1
Glasses
I have an admin-in-training, that requires access to see everything but NO access to change anything.I am on version ...
by Glasses Builder in Security 06-29-2020
0 3
0
3
ephrem3232
I'm looking for a splunk query for any suspicious IP address associated with an IP range that was already blocked in ...
by ephrem3232 Explorer in Security 06-26-2020
0 1
0
1
FritzWittwer
I have a user which needs to be able to write one specific lookup table which has to be shared globally. I have to co...
by FritzWittwer Path Finder in Security 06-25-2020
0 0
0
0
fman82
We have deployed Splunk Enterprise on an EC2 instance behind a classic ELB in AWS with HTTPS enabled (screenshots att...
by fman82 Explorer in Security 06-24-2020
0 4
0
4
Saravanakumar
Observation:Suddenly the SplunkSearchHead stopped cleaning the jobs in dispatch directory (/opt/splunk/var/run/splunk...
by Saravanakumar Observer in Security 06-22-2020
0 0
0
0
Saravanakumar
ObservationThe Nessus scan detected few certificate errors on the Splunk ports 8089 (management port), 8000(web-UI) a...
by Saravanakumar Observer in Security 06-22-2020
0 0
0
0
verifi81
When going through the SAML CONFIGURATION SETUP on splunk enterprise is the ENTITY ID a field that I can put anything...
by verifi81 Path Finder in Security 06-19-2020
0 0
0
0
denys_k
Hello,My company is one of Splunk partners, and our security team has several simple questions regarding Splunk Enter...
by denys_k Explorer in Security 06-19-2020
0 3
0
3
me74fhfd
Hi all, can you please help meI am calculating Shannon Entropy values for domains from single index and have two ques...
by me74fhfd Path Finder in Security 06-18-2020
0 0
0
0
OchinDave
For Splunk Cloud, I would like to enable user login to leverage LDAP to our Office365 but I am struggling to find the...
by OchinDave Engager in Security 06-16-2020
1 0
1
0
duneclarke2
WARN UserManagerPro - AQR not supported and user=username@domain.com information not found in cache or 404 User not f...
by duneclarke2 Explorer in Security 06-16-2020
2 0
2
0
knielsen
Hello, I just ran into the issue that I couldn't change the permission of a source based field extraction via GUI on ...
by knielsen Contributor in Security 06-15-2020
1 5
1
5
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...