Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
gabriel_vasseur
I have a correlation search that includes the field host and is enriched with all the usual fields such as host_nt_ho...
by gabriel_vasseur Contributor in Splunk Enterprise Security 05-14-2018
0 6
0
6
gkumarashanmuga
I have installed new app IP reputation , but not getting any data , Do i need to change any configurations or search ...
by gkumarashanmuga Explorer in Splunk Enterprise Security 05-14-2018
0 0
0
0
ayushi_kaushik
I have built an app (it contains eventtypes and tag) and have set it permission global. Apart from ES app, all its e...
by ayushi_kaushik New Member in Splunk Enterprise Security 05-14-2018
0 1
0
1
ikulcsar
Hi there, We are receiving logs from a Data Loss Prevention (DLP) system about what users access, etc and we want to...
by ikulcsar Communicator in Splunk Enterprise Security 05-14-2018
0 0
0
0
ikulcsar
Hi there! We are receiving logs from a NetApp file server about what user access, etc. Log format very similar/same ...
by ikulcsar Communicator in Splunk Enterprise Security 05-14-2018
0 0
0
0
mallempatisreed
hi All, When am trying to take kvstore backup in Security Search Head as part of upgrade process am getting below er...
by mallempatisreed Explorer in Splunk Enterprise Security 05-13-2018
0 1
0
1
panovattack
We have set the appropriate role and permissions on SA-ThreatInigence (write access) to enable ess_admin users to cre...
by panovattack Communicator in Splunk Enterprise Security 05-11-2018
0 0
0
0
masonmorales
I'm working on creating new notable events in Enterprise Security. In the notable event alert action, I'm trying to a...
by masonmorales Influencer in Splunk Enterprise Security 05-10-2018
0 3
0
3
pfabrizi
In our DEV space we are running a single search head with ES installed. We have built identity lookups from our HR da...
by pfabrizi Path Finder in Splunk Enterprise Security 05-09-2018
0 1
0
1
Mayanakhan
Hi How to install the Httpedgegrid on Search heads of Splunk Enterprise Security. @mayurr98
by Mayanakhan Explorer in Splunk Enterprise Security 05-09-2018
0 0
0
0
pbcahill
I’m in the process of on-boarding ADFS as a authentication and authorization log source for a number of applications ...
by pbcahill New Member in Splunk Enterprise Security 05-09-2018
0 0
0
0
tfrederick74656
I'm looking to provide two separate ES incident review views: one for rules that are live, and another for new rules ...
by tfrederick74656 Explorer in Splunk Enterprise Security 05-04-2018
0 0
0
0
tfrederick74656
I'm trying to follow the "Customize the Menu Bar" steps in https://docs.splunk.com/Documentation/ES/5.0.0/Admin/Custo...
by tfrederick74656 Explorer in Splunk Enterprise Security 05-04-2018
0 3
0
3
koshyk
I was looking into upgrade of ES from 4.1.x version to 4.7.x version. (alongside Splunk). I can see ES changed dramat...
by koshyk Super Champion in Splunk Enterprise Security 05-04-2018
0 6
0
6
heyyyyy
1
5
cafissimo
Hello, I am installing Splunk PCI app 3.5.0 on an environment that is made of a Search Head and two indexers (not clu...
by cafissimo Communicator in Splunk Enterprise Security 05-02-2018
0 1
0
1
N92
I have seen documents for this. As per document path should be below. Select Configure > Content Management. Click C...
by N92 Path Finder in Splunk Enterprise Security 05-01-2018
0 2
0
2
nitishk1
Hello, I am trying to send notable events to third party API. Can I use webhook to POST notable event details on thi...
by nitishk1 New Member in Splunk Enterprise Security 05-01-2018
0 2
0
2
MHibbin
Hi, We have a requirement to add some additional fields to events under "Incident Review" for IOCs (I have looked at...
by MHibbin Influencer in Splunk Enterprise Security 04-30-2018
1 9
1
9
daniel333
All, I though it would be nice for PCI guy to search the top right by PCI DSS req, say like "10.1" its working for ...
by daniel333 Builder in Splunk Enterprise Security 04-26-2018
1 1
1
1
kiranhar
We deploying Splunk enterprise security ( SIEM) solution) and it is in the final implementation stage. does anyone ha...
by kiranhar Explorer in Splunk Enterprise Security 04-26-2018
0 1
0
1
V4M51
difference between firewall log management and Splunk Security Log management as a SIEM
by V4M51 Engager in Splunk Enterprise Security 04-25-2018
0 6
0
6
atulod1
Hi I would like to ask for help regarding how to match the first dropdown list to the 2nd dropdown list. Here the ...
by atulod1 New Member in Splunk Enterprise Security 04-25-2018
0 0
0
0
dhodzic
Has anyone had luck defining Anomali Limo as a TAXII feed in Splunk Enterprise Security (ES)? Our internal STAXX app...
by dhodzic New Member in Splunk Enterprise Security 04-24-2018
0 0
0
0
N92
Can I add comment field as table attribute in incident review page. For that what would be field name so I can map it...
by N92 Path Finder in Splunk Enterprise Security 04-24-2018
0 3
0
3
Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...