Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
niks987
Hi All,Hope you all are doing well.I am very new to Splunk Enterprise security, and i need your help  to understand h...
by niks987 Explorer in Splunk Enterprise Security 10-17-2024
0 1
0
1
JackieTech
Hi all, I am trying to install Splunk Security Essentials into a single instance of Splunk with a downloaded file of ...
by JackieTech Explorer in Splunk Enterprise Security 10-16-2024
0 14
0
14
martaBenedetti
Hi, I'm trying to configure Drill-down Earliest Offset in my Notable from Adaptive Response Action. I'd like to run t...
by martaBenedetti Path Finder in Splunk Enterprise Security 10-14-2024
0 7
0
7
oz_dg
Hi everyone,Am having issues with the configuration of the AlienVault OTX feed in Splunk ES and would appreciate any ...
by oz_dg Explorer in Splunk Enterprise Security 10-14-2024
2 7
2
7
manikanthkoti
Hi everyone, Can you please help us to make the Secure cookies by doing below things. Setting HTTPOnly Flag to splu...
by manikanthkoti Explorer in Splunk Enterprise Security 10-07-2024
1 1
1
1
brownbag
I've seen someone use this traffic search function but can't find it myself:TrafficSearch.pngHow can I access this tr...
by brownbag Engager in Splunk Enterprise Security 10-03-2024
0 3
0
3
mjuestel2
Greetings,I found some useful savedsearches under SA-AccessProtection / DA-ESS-AccessProtection, which I am intereste...
by mjuestel2 Path Finder in Splunk Enterprise Security 10-02-2024
0 0
0
0
KingUs80
I'm trying to resolve an issue where Splunk sends email reports, but the information exported as an attachment uses a...
by KingUs80 Loves-to-Learn Lots in Splunk Enterprise Security 09-30-2024
0 5
0
5
Joesplunk
How to fix"Could not load lookup=LOOKUP-autolookup_prices"
by Joesplunk New Member in Splunk Enterprise Security 09-26-2024
0 1
0
1
jfournet
I am using the following html for my alert action data entry screen.  The tenant mulit-select does not show up in the...
by jfournet New Member in Splunk Enterprise Security 09-23-2024
0 0
0
0
echojacques
In Enterprise Security, you can configure Notable Event Suppressions. When adding/editing a suppression, which file ...
by echojacques Builder in Splunk Enterprise Security 09-23-2024
0 7
0
7
beano501
We are trying to ingest a STIX file into the Threat Intelligence Management, the STIX parses, but does not find anyth...
by beano501 Explorer in Splunk Enterprise Security 09-22-2024
0 1
0
1
rbenbenish
When running a search on the Incident Review dashboard where the search term is the <event_id> value or event_id="<ev...
by rbenbenish New Member in Splunk Enterprise Security 09-19-2024
0 0
0
0
user487596
Hi everyone!Is it possible to pass a parameter from search to the next "action|url" step? Like in description: $resul...
by user487596 Explorer in Splunk Enterprise Security 09-17-2024
0 0
0
0
hazem
We have a cluster with two search heads and two indexers. We need to install the Enterprise Security app on the searc...
by hazem Path Finder in Splunk Enterprise Security 09-17-2024
0 2
0
2
aluvian
Hi,We were using Splunk Enterprise (8.2.5) and ESS (7.2.0) on Debian 12. Everything was working fine until I upgraded...
by aluvian Loves-to-Learn Everything in Splunk Enterprise Security 09-16-2024
0 4
0
4
vikas_gopal
Hello Splunk ES experts ,  I want to make a query which will produce MTTD (something like by analyzing the time diffe...
by vikas_gopal Builder in Splunk Enterprise Security 09-14-2024
0 4
0
4
kareem
Salam guysI wrote the Correlation Search Query and added the Adaptive Response Actions (notable, risk analysis and se...
by kareem Explorer in Splunk Enterprise Security 09-14-2024
0 0
0
0
Splunkers2
Hi all,I'm having issues comparing user field in Palo Alto traffic logs vs last user reported by Crowdstrike/Windows ...
by Splunkers2 Observer in Splunk Enterprise Security 09-14-2024
0 3
0
3
VijaySrrie
Hi All,I need to download and install below app via command linehttps://splunkbase.splunk.com/app/263Please help me w...
by VijaySrrie Builder in Splunk Enterprise Security 09-13-2024
0 1
0
1
tuts
 Hello Splunk Community,I have .evtx files from several devices, and I would like to analyze them using Splunk Univer...
by tuts Path Finder in Splunk Enterprise Security 09-11-2024
0 3
0
3
wlight600
Hi! I'm creating custom alert action. I can use my alert action in save alert and Correlation search. But I meet ...
by wlight600 Engager in Splunk Enterprise Security 09-10-2024
0 14
0
14
tdth
Hi all,Has anyone had experience matching Linux audit logs to CIM before?I installed the Add-on for Unix and Linux, b...
by tdth Explorer in Splunk Enterprise Security 09-06-2024
0 3
0
3
zksvc
I Have 60 Correlation Search in Content Management Some of my Correlation Search doesn't trigger to Incident Review b...
by zksvc Contributor in Splunk Enterprise Security 09-05-2024
0 0
0
0
tuts
Hello, I am currently working in a SOC, and I want to test rules in Splunk ES using the BOTSv2 dataset. How can I con...
by tuts Path Finder in Splunk Enterprise Security 09-03-2024
0 1
0
1
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors