Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
feridmehtiyev1
Hello, I am a cybersecurity engineering student and I am currently in the final stage of an international cybersecuri...
by feridmehtiyev1 Engager in Splunk Enterprise Security 7 hours ago
1 9
1
9
AvocadoLogs
We are setting up Mission Control as the main dashboard in our operations center (which handles both NOC and SOC sinc...
by AvocadoLogs New Member in Splunk Enterprise Security yesterday
0 0
0
0
Latefa
Hi,Does Splunk Enterprise Security 8.x support JSON feeds directly as a URL-based threat intelligence source?If yes, ...
by Latefa New Member in Splunk Enterprise Security Friday
0 1
0
1
sergzin
Hi All,Is there any documentation describing setting this app for integration between Splunk ES and Google SecOps? I ...
by sergzin New Member in Splunk Enterprise Security Tuesday
0 0
0
0
neerajs_81
Hello, Like any other ES user, we have threat intel feeds configured that came along with box.  How can i view the ac...
by neerajs_81 Builder in Splunk Enterprise Security 2 weeks ago
0 2
0
2
mohsplunking
Hello Splunkers,I have a question around integration of Salesforce with Splunk , I see there are two Add-on available...
by mohsplunking Path Finder in Splunk Enterprise Security 3 weeks ago
0 1
0
1
0xAli
Hi,I have rule to detect some suspicious activity and want to add the source IP into the ES Threat Intel, However Thr...
by 0xAli Path Finder in Splunk Enterprise Security a month ago
0 1
0
1
Ian0706
I have recently installed Splunk Enterprise Security v8.4 on a fresh Splunk instance after successfully using v8.2 on...
by Ian0706 Explorer in Splunk Enterprise Security 08-20-2026
0 5
0
5
splunker_ak
Following on from an earlier thread where investigations appear in the Analyst Queue for a second and then vanish. Th...
by splunker_ak Explorer in Splunk Enterprise Security 08-20-2026
0 0
0
0
maheshnc
In splunk ES, a user is unable to edit/delete comments for most of the notables in incident review, however the same ...
by maheshnc Path Finder in Splunk Enterprise Security 08-19-2026
0 0
0
0
Fregault
Working on a large Splunk Cloud engagement (Classic Experience, ES on the premium search head) and want a sanity chec...
by Fregault New Member in Splunk Enterprise Security 08-16-2026
0 0
0
0
splunkreal
Hello, when using these queries I can see difference between HF and IDX measures :index=_internal source=*metrics.log...
by splunkreal Influencer in Splunk Enterprise Security 08-07-2026
0 2
0
2
0xAli
Hi all,Anyone face the below, and how to get ride of it:
by 0xAli Path Finder in Splunk Enterprise Security 08-06-2026
0 4
0
4
Safia_LSD
Hello,Since the Splunk Enterprise Security Certified Admin certification is now classified as a legacy certification,...
by Safia_LSD Engager in Splunk Enterprise Security 08-06-2026
1 2
1
2
kjain041523
why the notable disappear from mission control after clicking start investigation button
by kjain041523 Observer in Splunk Enterprise Security 08-04-2026
0 0
0
0
Agent
Environment: Splunk Enterprise Security 8.5.1 (on-prem)I have "Hide findings" turned on under Configure → Findings an...
by Agent Explorer in Splunk Enterprise Security 07-31-2026
0 0
0
0
_Raj
Hi,I just want to understand what is the exact difference between query and search.Thanks
by _Raj Path Finder in Splunk Enterprise Security 07-30-2026
0 2
0
2
dairontorresz
Hi everyone,I'm currently facing an issue that I have not been able to resolve and would appreciate your guidance.We ...
by dairontorresz Engager in Splunk Enterprise Security 07-28-2026
0 1
0
1
vvanlier
The "Local Processes Tracker"  from SA-EndpointProtection maintains a list of all processes on each system and the fi...
by vvanlier Explorer in Splunk Enterprise Security 07-28-2026
2 3
2
3
Elina
Greetings everyone,I was using ES 8.3 and when I created a finding-group based on a event based finding it only showe...
by Elina Engager in Splunk Enterprise Security 07-26-2026
0 0
0
0
peterschloenske
Hi,I'm currently looking into ES entity zones and am a bit confused about the process.The cim data model documentatio...
by peterschloenske Explorer in Splunk Enterprise Security 07-22-2026
0 0
0
0
ljvc
Hi there,we're currently migrating to ES 8 and need to see Work Notes (comments) provided by analysts in some dashboa...
by ljvc Path Finder in Splunk Enterprise Security 07-22-2026
1 16
1
16
fraserphillips
I'm trying to add assets and users from an index that is not apart of the standard predefined sources.   I can't  see...
by fraserphillips Explorer in Splunk Enterprise Security 07-17-2026
1 1
1
1
AleCanzo
Hi everyone,I'm using Splunk Enterprise Security 8.5.1 and I'm seeing some unexpected behavior when adding comments t...
by AleCanzo Path Finder in Splunk Enterprise Security 07-15-2026
0 0
0
0
AceX
My company is doing SOC for our partners, we integrated two company in our ES we have one site it is not multisite so...
by AceX Path Finder in Splunk Enterprise Security 07-10-2026
0 17
0
17
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...