Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
Crashfry
I'm running into an issue with Enterprise Security (ES) - correlation with event types with Add-ons. The example I ...
by Crashfry Path Finder in Splunk Enterprise Security 09-17-2018
0 1
0
1
snigdhasaxena
I want to check the severity of notable events so that I can hardcode the value of urgency without using lookups. Is ...
by snigdhasaxena Communicator in Splunk Enterprise Security 09-17-2018
0 4
0
4
pkievisas
Users report us suspicious emails for threat analysis. My idea is to import these emails into Splunk ES and automate ...
by pkievisas New Member in Splunk Enterprise Security 09-15-2018
0 0
0
0
ekost
Running ES 5.1 on Splunk 7.1. The asset lookups have been working fine. This morning the SRC and dest fields display ...
by ekost Splunk Employee Splunk Employee in Splunk Enterprise Security 09-14-2018
0 1
0
1
Lowell
I'm trying to make ldapfilter augment my results. I have a DN that I'm trying to resolve to an account name (sAMAcco...
by Lowell Super Champion in Splunk Enterprise Security 09-14-2018
0 3
0
3
markerton
I'm trying to run a simple search that shows only specific results and excludes the rest. The results are coming fr...
by markerton New Member in Splunk Enterprise Security 09-13-2018
0 1
0
1
christianubeda
Hi team! I need help with a search. I have 2 indexes and I want to match both for an IP field. If they match, I wa...
by christianubeda Path Finder in Splunk Enterprise Security 09-13-2018
0 1
0
1
ikulcsar
Hi, Because of license renew/upgrade: is there any way to report/estimate the license volume processed by Enterprise...
by ikulcsar Communicator in Splunk Enterprise Security 09-13-2018
0 4
0
4
lakshman239
I understand we can use the following to look at the investigations created which are 'Active'. |inputlookup append=...
by lakshman239 Influencer in Splunk Enterprise Security 09-12-2018
0 9
0
9
DEAD_BEEF
On new install of Splunk Enterprise Security (version 4.7.6), I am seeing the following errors, once an hour. I incl...
by DEAD_BEEF Builder in Splunk Enterprise Security 09-12-2018
0 1
0
1
nicolociraci
Hello, I'm unable to get field validation in a Custom Adaptive Response Action in Splunk Enterprise Security. What I...
by nicolociraci New Member in Splunk Enterprise Security 09-12-2018
0 0
0
0
christianubeda
Hi team! I'm new here, very first time with Splunk. I need stats from two different indexes but only if they match....
by christianubeda Path Finder in Splunk Enterprise Security 09-11-2018
0 1
0
1
SunilMaharishi
Hello Team , I have to create a report using [trendmicro AV logs] which should include the below details: — Monthly...
by SunilMaharishi Path Finder in Splunk Enterprise Security 09-11-2018
0 0
0
0
reubenjoseph
I have been trying to get some statistics around the Threat Intel that is being pushed into the the comes into Splunk...
by reubenjoseph Explorer in Splunk Enterprise Security 09-11-2018
0 3
0
3
fatboy3388
Hi, All i want to do is just find out email event which the (sender_email _address) is different with the (return_a...
by fatboy3388 New Member in Splunk Enterprise Security 09-09-2018
0 5
0
5
agcorreia_asml
Hi guys, Does anyone have successfully get the DLP incident logs from ePO to Mcafee? I'm using dbconnect with epo APP...
by agcorreia_asml Engager in Splunk Enterprise Security 09-08-2018
2 5
2
5
rajanshrivastav
I'm not able to close notable alerts in the Incident Review but now the alert drill-down doesn’t seem to be functiona...
by rajanshrivastav Path Finder in Splunk Enterprise Security 09-08-2018
0 1
0
1
austincisneros
I have medical compliance questions from Auditors about the certification through CMS www.cms.gov They have tried to ...
by austincisneros New Member in Splunk Enterprise Security 09-07-2018
0 3
0
3
RicoSuave
I am experiencing periodic duplicate notable events in my search head cluster. I have a feeling this has something to...
by RicoSuave Builder in Splunk Enterprise Security 09-07-2018
0 1
0
1
christianubeda
Hello team! I'm new and I need some help, I would like to be able to upload information that is in a CSV to Splunk....
by christianubeda Path Finder in Splunk Enterprise Security 09-07-2018
0 11
0
11
christianubeda
Hello team! I'm new to this and I need help. I would like to upload a CSV file with the following structure to Splun...
by christianubeda Path Finder in Splunk Enterprise Security 09-07-2018
0 0
0
0
tfrandsen
Hi Experts, I am trying to setup a glasstable containing the result from cvss score field. I seem to get other res...
by tfrandsen New Member in Splunk Enterprise Security 09-06-2018
0 6
0
6
rajanshrivastav
I'm not getting edit option in incident review page under SplunkEnterpriseSecuritySuite. I'm using Splunk App for En...
by rajanshrivastav Path Finder in Splunk Enterprise Security 09-06-2018
0 4
0
4
pradeep577
Hi, Has anybody tried the below scenario? If yes, can I get some guidance? Malicious IPs are shown on Splunk dashbo...
by pradeep577 Path Finder in Splunk Enterprise Security 09-05-2018
0 0
0
0
nisargsoni
We have integrated our Splunk add-on with Splunk Enterprise Security (Threat Intelligence) where we have scheduled a ...
by nisargsoni New Member in Splunk Enterprise Security 09-05-2018
0 1
0
1
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...