Security

Security
Community Activity
brdr
We have about 1000+ users in our Splunk environment and we are getting ready for an audit. Specifically, we are revie...
by brdr Contributor in Security 05-09-2019
0 3
0
3
splunkgk
Hi, My splunk app is configured with LDAP authentication method and there is a bunch of users who left and they need...
by splunkgk Path Finder in Security 05-08-2019
0 3
0
3
swamysanjanaput
I was using the below search query to find the failed logins by domain admins however i was asked not to use lookup f...
by swamysanjanaput Explorer in Security 05-08-2019
0 1
0
1
andrewtrobec
Hello, As the question title suggests, I am looking for any technical documentation that concerns the Native Splunk A...
by andrewtrobec Motivator in Security 05-07-2019
0 2
0
2
saibal6
Hi Experts, I have admin permission to login into the splunk. So whenever I run a report, it's taking hardly 2 secon...
by saibal6 Path Finder in Security 05-07-2019
0 2
0
2
ialislam
When attempting to SendAlert to trigger action from our Malwarebytes Splunk App. I receive the following Error in Sp...
by ialislam New Member in Security 05-06-2019
0 2
0
2
bugnet
Hi all, I'm working with app "misp42splunk" which can be used to extract information from the MISP instance. The n...
by bugnet Path Finder in Security 05-05-2019
1 0
1
0
shodudley
I'm working with Splunk Universal Forwarder 6.5.2 and am trying to configure a monitor on the docker volumes director...
by shodudley New Member in Security 05-02-2019
0 0
0
0
robertlynch2020
HI I want to create a 100% read only user, how do i remove the setting. I hvae tried to remove the "list setting". B...
by robertlynch2020 Influencer in Security 05-02-2019
0 0
0
0
adetokunbowahab
Hello, I am trying to build and add on using the Splunk builder app to make API calls but using certificates for aut...
by adetokunbowahab New Member in Security 05-02-2019
0 0
0
0
khusain_splunk
The 'NotBefore' condition could not be verified successfully. The SAML response is not valid My IDP provider is ADFS.
by khusain_splunk Splunk Employee Splunk Employee in Security 04-30-2019
0 1
0
1
GenRockeR
Hi, guys. I've Splunk Search Head cluster and I want add new member to this cluster. I use documentation from https:...
by GenRockeR Explorer in Security 04-30-2019
0 2
0
2
AshChakor
I am able to setup proxy on NGINX as per the instructions on http://dev.splunk.com/view/javascript-sdk/SP-CAAAEWQ. Ho...
by AshChakor Path Finder in Security 04-29-2019
0 1
0
1
jtjxa
Hello, I'm trying to do something very simple. I am trying to give a role the ability to edit the permissions of kno...
by jtjxa New Member in Security 04-29-2019
0 0
0
0
thomasbchurch
We audit the security logs looking for password compromises. A user will put the password in as the username and res...
by thomasbchurch New Member in Security 04-29-2019
0 5
0
5
newbie2tech
Hi Team, Wanted to check if any of you have used LDAP only for Authentication and then handled the roles using splun...
by newbie2tech Communicator in Security 04-26-2019
0 5
0
5
agentsofshield
Hi! So I managed to configure LDAP authentication for the search head, but what if I want to make a user connect thr...
by agentsofshield Path Finder in Security 04-25-2019
1 1
1
1
rohitvjoshi
Hi Splunkers, we are using clustered enviornment, we having 3 SH .We have notified by infra team that one of our se...
by rohitvjoshi Path Finder in Security 04-24-2019
0 2
0
2
Sukisen1981
Hi, I have checked many answers and done some changes but I continue to receive site not secure screen first time wh...
by Sukisen1981 Champion in Security 04-24-2019
1 8
1
8
liquidclay23
Hey Splunkers, This maybe less of a question and more of a comment. The "Configure Splunk forwarding to use signed c...
by liquidclay23 Explorer in Security 04-19-2019
1 1
1
1
nick405060
Current: index=_audit user!="splunk-system-user" user!="n/a" user!="MYUSER" user!=testuser* (action="login attempt")...
by nick405060 Motivator in Security 04-19-2019
0 2
0
2
dpapenbro
Running V7.1, but just Installed a new forwarder and received this response: This appears to be your first time run...
by dpapenbro New Member in Security 04-19-2019
0 5
0
5
dbedoya
Hi, I have 124 entries configured, but I can only enable 102, and if I enable one after 102, the following error mess...
by dbedoya New Member in Security 04-18-2019
0 0
0
0
romulusc
Tried to migrate KV store using the splunk migrate migrate-kvstore cmd and got another error when looking at the migr...
by romulusc New Member in Security 04-18-2019
0 0
0
0
4stringdave
Can the Power User Exam be taken without taking the User Exam first?
by 4stringdave New Member in Security 04-18-2019
0 1
0
1
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...