Security

Security
Community Activity
Orange_girl
Hello, I am running SPLUNK 9.1.2 on Linux and ever since I installed a new internal certificate, I am not able to run...
by Orange_girl Loves-to-Learn Everything in Security 07-17-2024
0 2
0
2
heskez
Hi there, I'd like to have a dedicated threat intel feed which goes to a custom created lookup (non-default), is that...
by heskez Engager in Security 07-16-2024
0 1
0
1
tuts
While using Splunk ES, we noticed that correlation searches were setTo an incorrect security field on the Incident Re...
by tuts Path Finder in Security 07-14-2024
0 10
0
10
Moldy
Trying to create a search that will show which capabilities a user has used within the last year.
by Moldy Engager in Security 07-12-2024
0 2
0
2
SplunkExplorer
Hi Guys, we have a doubt reagarding the user that execute Splunk on a linux environment.Until now, we have always avo...
by SplunkExplorer Contributor in Security 07-12-2024
0 2
0
2
karn
I would like to disable some local accounts temporary. I cannot find disable or suspend button in access controls set...
by karn Path Finder in Security 07-12-2024
0 3
0
3
AkhilSreek
Hey ,Just heard about CVE-2024-5535 on splunkforwarder agent 9.0.9 for Openssl 1.0.2zj , Is this a real one ? Do we n...
by AkhilSreek New Member in Security 07-11-2024
0 1
0
1
SplunkDash
Hello.I have some issues with field parsing for the CSV files using props configuration. I should be getting 11 field...
by SplunkDash Motivator in Security 07-11-2024
0 6
0
6
nabhosal
What capabilities I need to give to particular user on master node in order to view monitoring console? Right now I ...
by nabhosal New Member in Security 07-10-2024
0 9
0
9
Chiranjeev
I am having issues with action extraction on my windows addon . for example the eventcode 4624 should have an action ...
by Chiranjeev Explorer in Security 07-08-2024
0 6
0
6
sylbaea
Hello, I have a Search Head Cluster configured with SAML authentication (ADFS)... For an existing SAML group (alrea...
by sylbaea Communicator in Security 07-08-2024
0 17
0
17
tuts
Why is it that every time I set the event under (Security Domain=NETWORK) from the Content Management page, the value...
by tuts Path Finder in Security 07-08-2024
0 0
0
0
jbsplunk
01-24-2012 17:35:39.483 -0800 ERROR SSLCommon - Can't read key file /opt/splunk/etc/auth/server.pem errno=101077092 e...
by jbsplunk Splunk Employee Splunk Employee in Security 07-04-2024
4 8
4
8
devd25
When I drag an Indexer or Heavy Forwarder icon in Visio from Splunk stencil, it is not displayed properly. Image atta...
by devd25 Explorer in Security 07-03-2024
1 8
1
8
Justin_M
Hi All,We have Splunk Security ENT 6.6.2 - EOL, I know! our admins guys are working on upgrading.My Problem.We create...
by Justin_M New Member in Security 07-03-2024
0 1
0
1
vksplunk1
Hi We are Getting "GnuTLS handshake retry returned error" when try to communicate with ForeScout". Any suggestion 
by vksplunk1 Explorer in Security 07-02-2024
0 1
0
1
sujald
Hey can anybody help with this task of how to find an account with the most login attempts  in the 4624 events within...
by sujald New Member in Security 07-01-2024
0 3
0
3
woodcock
We deployed our first Splunk in AWS using the tooling in AWS to do this and see that there is unallowed traffic calli...
by Esteemed Legend in Security 06-30-2024
1 1
1
1
VijaySrrie
Hi Team,How to check the expiry date of a certificate in splunk windows using command lineUser is having local admin ...
by VijaySrrie Builder in Security 06-30-2024
0 1
0
1
corti77
Hi,I am runnig Splunk 9.0.9 with Splunk Add-on for Sysmon 4.0.1 and Sysmon Security Monitoring App for Splunk 4.0.13....
by corti77 Contributor in Security 06-25-2024
0 0
0
0
lguplusIdaas
my SAML Response to Splunk. <?xml version="1.0" encoding="UTF-8" standalone="no"?><samlp:Response xmlns:samlp="urn:oa...
by lguplusIdaas New Member in Security 06-19-2024
0 0
0
0
lguplusIdaas
It says, "If you save your IdP certificate under $SPLUNK_HOME/etc/auth/idpCerts, please leave it blank." If you don't...
by lguplusIdaas New Member in Security 06-19-2024
0 0
0
0
marketplace
Hi all,I am currently testing the Http Event Collector (HEC) with a Splunk Cloud trial account. All I do is post data...
by marketplace Loves-to-Learn in Security 06-19-2024
0 4
0
4
kaboom1
Hello all,I need to configure SAML/SSO with Splunk but i m having the following issues:- I have 3 search heads in a c...
by kaboom1 Explorer in Security 06-19-2024
0 0
0
0
AL3Z
Hi,I want to learn the Splunk Enterprise Security from scratch could anyone pls share the links?Thanks.
by AL3Z Builder in Security 06-19-2024
0 3
0
3
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...