Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
Alkern
Guys need help,We have successfully installed the Splunk AI Assistant application on our Search Head. However, we are...
by Alkern Engager in Splunk Enterprise Security 3 weeks ago
0 4
0
4
splunkreal
Hello, us there still Intermediate findings column for findings in analyst queue for Event based detections?Thanks.
by splunkreal Influencer in Splunk Enterprise Security 3 weeks ago
0 5
0
5
AceX
Guys I need to collect data and map to CIM for Enterprise Security senhasegura data but I could not find any app or a...
by AceX Loves-to-Learn Lots in Splunk Enterprise Security 4 weeks ago
0 1
0
1
cseiler-gmp
Is there a way to bulk update enabled ESCU detections when a new version with a lot of metadata changes like the MITR...
by cseiler-gmp New Member in Splunk Enterprise Security a month ago
0 2
0
2
Alkern
Our company is currently using Splunk Enterprise Security, and we would like to ask a question regarding available fe...
by Alkern Engager in Splunk Enterprise Security a month ago
0 1
0
1
Wohamed_wakkad
What is the relationship between Splunk accelerated data models stored in the datamodel_summary index and the normal ...
by Wohamed_wakkad Explorer in Splunk Enterprise Security 05-05-2026
0 5
0
5
Sherminator
Hello, We have a large number of dashboards and queries in our Splunk instance, and some of those are meant for monit...
by Sherminator Engager in Splunk Enterprise Security 04-30-2026
0 3
0
3
0xAli
Hi Everyone,We have integrated Crowdstrike falcon with splunk and we retrieved the IOC in index=cs_ioc.Using the belo...
by 0xAli Explorer in Splunk Enterprise Security 04-25-2026
0 3
0
3
jordanmorgan
Unexpected status for to fetch REST endpoint uri=https://127.0.0.1:8089/services/storage/investigation/investigation?...
by jordanmorgan Observer in Splunk Enterprise Security 04-24-2026
0 1
0
1
KevHaze
We are currently in the process of upgrading from ES 7.x to ES 8.x and are performing a data validation/parity checks...
by KevHaze Explorer in Splunk Enterprise Security 04-21-2026
0 3
0
3
0xAli
Hi Everyone,I have a clustered SH (Install ES App) + Adhoc search head.I need to know what is the role of the adhoc S...
by 0xAli Explorer in Splunk Enterprise Security 04-17-2026
0 5
0
5
dspencer
Hello,I created a new role that is the same as ess_analyst but it doesn't have any inheritance, all the capabilities ...
by dspencer Path Finder in Splunk Enterprise Security 04-10-2026
0 4
0
4
lmaclean
Hi,I am having trouble after coming from ES 7.x going through creating what I thought might be a simple Event Based D...
by lmaclean Path Finder in Splunk Enterprise Security 04-09-2026
0 3
0
3
akai
Hello,I have create a custom role and assigned the same permissions as ess_user, including adding it to the enforce_e...
by akai Explorer in Splunk Enterprise Security 04-09-2026
0 6
0
6
ljvc
Hi there,we're currently migrating to ES 8 and need to see Work Notes (comments) provided by analysts in some dashboa...
by ljvc Path Finder in Splunk Enterprise Security 04-08-2026
0 14
0
14
Sky
Hi everyone,I’m seeing a discrepancy with the Risk Modular Alert Action in Splunk ES. When triggering the risk action...
by Sky New Member in Splunk Enterprise Security 04-07-2026
0 1
0
1
wrknh
After upgrading my Splunk Enterprise Security environment from 7.3.3 to 8.3.0, I’m seeing the following error on the ...
by wrknh Engager in Splunk Enterprise Security 04-01-2026
0 2
0
2
Ian0706
I have recently installed Splunk Enterprise Security v8.4 on a fresh Splunk instance after successfully using v8.2 on...
by Ian0706 Explorer in Splunk Enterprise Security 03-30-2026
0 4
0
4
David_Loureiro
Hello,I am facing an issue in Splunk Enterprise 10.0.2 with ES installed when opening Apps > Find More Apps.The page ...
by David_Loureiro Observer in Splunk Enterprise Security 03-29-2026
0 1
0
1
openbase
After upgrading from ES 8.1 to ES 8.4, automation rules are no longer functioning.When detections are triggered based...
by openbase Engager in Splunk Enterprise Security 03-27-2026
1 1
1
1
tsa
We are observing delayed ingestion of logs from neuvector application, via syslog method 
by tsa New Member in Splunk Enterprise Security 03-19-2026
0 3
0
3
sirius2sun
Hi I am not able to download ES trail for Splunk enterprise
by sirius2sun New Member in Splunk Enterprise Security 03-13-2026
0 1
0
1
christosb
Hello,I am trying to optimize my infrastructures datamodels. I am following this guide from Lantern:Optimizing data m...
by christosb Loves-to-Learn in Splunk Enterprise Security 03-12-2026
0 3
0
3
amimulahasun
Hi everyone,I'm currently working with Splunk Enterprise Security and running into an issue when trying to enable mul...
by amimulahasun Explorer in Splunk Enterprise Security 03-10-2026
0 2
0
2
joeharv
Does the Splunk Add-on for ServiceNow support separate endpoint configurations for Automated Alert Actions and the ma...
by joeharv New Member in Splunk Enterprise Security 03-09-2026
0 0
0
0
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...
Top Solution Authors