Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
brober27
Please can anyone help in suggest search SPL command line to issue on an URL field in order to detect a CSRF attack ...
by brober27 New Member in Splunk Enterprise Security 05-27-2018
0 0
0
0
daniel333
All, Mind is drawing a blank. I want to normalize netstat output and then do a lookup on the destination fields to ...
by daniel333 Builder in Splunk Enterprise Security 05-25-2018
0 1
0
1
jhigginsmq
Hi. We've just upgraded to Splunk 7.1 on our ES search head, as well as upgrading ES from 5.0 to 5.1 to meet the comp...
by jhigginsmq Path Finder in Splunk Enterprise Security 05-25-2018
0 2
0
2
saurabh_tek11
How can we Integrate them so that both (Manage Engine and Splunk ES Incident review) works in sync
by saurabh_tek11 Communicator in Splunk Enterprise Security 05-25-2018
0 3
0
3
BAPA157
Hello, I have figured out a strange behavior of Splunk correlation searches. I'm using Splunk Enterprise version 7.0...
by BAPA157 Engager in Splunk Enterprise Security 05-25-2018
0 0
0
0
shartwell
I created an alert action using the latest verison of Add-on Builder (v2.2) using some other Splunk answers posts as ...
by shartwell Explorer in Splunk Enterprise Security 05-24-2018
0 0
0
0
shayhibah
I have multiple logs with the same unique field. for instance: Time: 10:00:00 Log-id: 0x1212 Message: ABCD Time: 10:...
by shayhibah Path Finder in Splunk Enterprise Security 05-24-2018
0 4
0
4
raghu_yara
Hi, using this query | from datamodel:"Vulnerabilities"."Vulnerabilities" |stats count by signature getting result 2...
by raghu_yara New Member in Splunk Enterprise Security 05-24-2018
0 1
0
1
kwchang_splunk
One of my Splunk Enterprise Security customer's complained that sometimes the notable events are not created even whe...
by kwchang_splunk Splunk Employee Splunk Employee in Splunk Enterprise Security 05-21-2018
0 4
0
4
bbraun
Hi guys, Im not sure how to go about this. We currently have the Excessive Failed Logins Correlation Search enabled...
by bbraun New Member in Splunk Enterprise Security 05-21-2018
0 0
0
0
adamsmith47
Let me first say, I'm sure I could write a search that essentially returns what I'm looking for, however due to the a...
by adamsmith47 Communicator in Splunk Enterprise Security 05-18-2018
0 1
0
1
shahchintant
If events are coming in from heavy forwarder 1 to heavy forwarder 2, is is possible to change the index name on HF B ...
by shahchintant Engager in Splunk Enterprise Security 05-18-2018
0 5
0
5
gilbxrtx_7
I am working on eval expression. I have a set of data and I want to evaluate a field such that I only extract login a...
by gilbxrtx_7 New Member in Splunk Enterprise Security 05-17-2018
0 2
0
2
emmanuelpeter
So basically I'm trying to generate an event when a risk score above 100 is generated, I've come up with the below se...
by emmanuelpeter New Member in Splunk Enterprise Security 05-17-2018
0 3
0
3
npavlidis
When a file is manually uploaded in Enterprise Security(ES), you can (and have to) define File Name, File to be uploa...
by npavlidis Engager in Splunk Enterprise Security 05-17-2018
0 4
0
4
nb1030
In the Threat Activity Detected IR correlation search, it calls for stuff from the "Threat Intelligence" Data Model. ...
by nb1030 New Member in Splunk Enterprise Security 05-16-2018
0 1
0
1
MonkeyK
I am trying to find non-alexa top 1 million domain requests. I am getting alexa_by_str.csv from https://s3.amazonaws...
by MonkeyK Builder in Splunk Enterprise Security 05-16-2018
0 13
0
13
gilbxrtx_7
I am working on aligning my own data to Splunk Enterprise Security's data model. Big error 1: I draft out my search...
by gilbxrtx_7 New Member in Splunk Enterprise Security 05-16-2018
0 0
0
0
trevisbecker
I have a need to disable any version of tls below version 1.2. I've done this at the main splunk server, but there a...
by trevisbecker New Member in Splunk Enterprise Security 05-15-2018
0 0
0
0
praxis_mcvt
Is it only me or the following apps are not downloadable : https://splunkbase.splunk.com/app/3454/ https://splunkbas...
by praxis_mcvt New Member in Splunk Enterprise Security 05-15-2018
0 1
0
1
chiltonb
Is there a way to force a notable event in Splunk Enterprise Security to be critical? We have certain notables that ...
by chiltonb Explorer in Splunk Enterprise Security 05-15-2018
0 7
0
7
samlinsongguo
Hi Guys I am looking for do a report on any log source or index setting was changed in last 7 days, where can I get t...
by samlinsongguo Communicator in Splunk Enterprise Security 05-15-2018
0 3
0
3
eliyyah
If this has already been covered, please provide a link, but I haven't seen anything. My organization uses Splunk Cl...
by eliyyah Explorer in Splunk Enterprise Security 05-15-2018
0 6
0
6
920087764
Hello all I have a problem on my splunk. The monitoring console illustrates the forwarded traffic from forwarders to ...
by 920087764 Engager in Splunk Enterprise Security 05-15-2018
0 10
0
10
pfgrobler
I have a search that returns a set of source and dest IP addresses. Index= ..... | table src, dest I want to che...
by pfgrobler New Member in Splunk Enterprise Security 05-14-2018
0 1
0
1
Get Updates on the Splunk Community!

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...