Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
jfournet
I am using the following html for my alert action data entry screen.  The tenant mulit-select does not show up in the...
by jfournet New Member in Splunk Enterprise Security 09-23-2024
0 0
0
0
echojacques
In Enterprise Security, you can configure Notable Event Suppressions. When adding/editing a suppression, which file ...
by echojacques Builder in Splunk Enterprise Security 09-23-2024
0 7
0
7
beano501
We are trying to ingest a STIX file into the Threat Intelligence Management, the STIX parses, but does not find anyth...
by beano501 Explorer in Splunk Enterprise Security 09-22-2024
0 1
0
1
rbenbenish
When running a search on the Incident Review dashboard where the search term is the <event_id> value or event_id="<ev...
by rbenbenish New Member in Splunk Enterprise Security 09-19-2024
0 0
0
0
user487596
Hi everyone!Is it possible to pass a parameter from search to the next "action|url" step? Like in description: $resul...
by user487596 Explorer in Splunk Enterprise Security 09-17-2024
0 0
0
0
hazem
We have a cluster with two search heads and two indexers. We need to install the Enterprise Security app on the searc...
by hazem Path Finder in Splunk Enterprise Security 09-17-2024
0 2
0
2
aluvian
Hi,We were using Splunk Enterprise (8.2.5) and ESS (7.2.0) on Debian 12. Everything was working fine until I upgraded...
by aluvian Loves-to-Learn Everything in Splunk Enterprise Security 09-16-2024
0 4
0
4
vikas_gopal
Hello Splunk ES experts ,  I want to make a query which will produce MTTD (something like by analyzing the time diffe...
by vikas_gopal Builder in Splunk Enterprise Security 09-14-2024
0 4
0
4
kareem
Salam guysI wrote the Correlation Search Query and added the Adaptive Response Actions (notable, risk analysis and se...
by kareem Explorer in Splunk Enterprise Security 09-14-2024
0 0
0
0
Splunkers2
Hi all,I'm having issues comparing user field in Palo Alto traffic logs vs last user reported by Crowdstrike/Windows ...
by Splunkers2 Observer in Splunk Enterprise Security 09-14-2024
0 3
0
3
VijaySrrie
Hi All,I need to download and install below app via command linehttps://splunkbase.splunk.com/app/263Please help me w...
by VijaySrrie Builder in Splunk Enterprise Security 09-13-2024
0 1
0
1
tuts
 Hello Splunk Community,I have .evtx files from several devices, and I would like to analyze them using Splunk Univer...
by tuts Path Finder in Splunk Enterprise Security 09-11-2024
0 3
0
3
wlight600
Hi! I'm creating custom alert action. I can use my alert action in save alert and Correlation search. But I meet ...
by wlight600 Engager in Splunk Enterprise Security 09-10-2024
0 14
0
14
tdth
Hi all,Has anyone had experience matching Linux audit logs to CIM before?I installed the Add-on for Unix and Linux, b...
by tdth Explorer in Splunk Enterprise Security 09-06-2024
0 3
0
3
zksvc
I Have 60 Correlation Search in Content Management Some of my Correlation Search doesn't trigger to Incident Review b...
by zksvc Contributor in Splunk Enterprise Security 09-05-2024
0 0
0
0
tuts
Hello, I am currently working in a SOC, and I want to test rules in Splunk ES using the BOTSv2 dataset. How can I con...
by tuts Path Finder in Splunk Enterprise Security 09-03-2024
0 1
0
1
corti77
Hi,I am testing the Security Essentials App 3.8.0 in Splunk 9.0.8, and I found the same issue while trying to activat...
by corti77 Contributor in Splunk Enterprise Security 09-02-2024
0 4
0
4
tadecleid
I found a similar post that did not quite fit the bill of what I am trying to do.I want to be able to create a link g...
by tadecleid New Member in Splunk Enterprise Security 09-02-2024
0 0
0
0
splunk_user9968
I would like to create a search with data models where my event id is 39. However, there is no datamodel that fulfill...
by splunk_user9968 New Member in Splunk Enterprise Security 08-27-2024
0 1
0
1
f_666dhn
I have lookup file bad_domain.csvbaddomain.combaddomain2.combaddomain3.com Then i want to search from proxy log, who ...
by f_666dhn Explorer in Splunk Enterprise Security 08-13-2024
0 1
0
1
japo86
I request that there be the ability to create groups of users in enterprise security so that when you need to add the...
by japo86 New Member in Splunk Enterprise Security 08-02-2024
0 1
0
1
vtalanki
Hi All, I want to enable SSL for Splunk management port(8089) for securing inter-splunk communications. I have below ...
by vtalanki Path Finder in Splunk Enterprise Security 08-01-2024
0 4
0
4
ThuLe
Hello,I'm trying to add new/existing key indicator searches to my dashboard in ES, but the edit toolbar does not have...
by ThuLe Explorer in Splunk Enterprise Security 07-30-2024
0 3
0
3
Unnamed16
I am wondering why Deployment Server is full and the only stored in this server is Deployment Server Ta’s and .Conf t...
by Unnamed16 Loves-to-Learn in Splunk Enterprise Security 07-22-2024
0 2
0
2
Rhidian
Is it possible to use a lookup file in the Noteble Event supression say to look up a list of assets/enviroments that ...
by Rhidian Path Finder in Splunk Enterprise Security 07-18-2024
0 4
0
4
Get Updates on the Splunk Community!

From Raw Data to Executive-Ready Stories, Faster

Build Data Stories for Every Audience  A dashboard is rarely just a dashboard. It might be the view an ...

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...