Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
ramesh_babu71
Hello, I'm trying out a Adaptive response action of VirusTotal which i created by following this site http://dev.spl...
by ramesh_babu71 Path Finder in Splunk Enterprise Security 11-27-2017
0 3
0
3
10306629
"Search peer has the following message: Review roles for unnecessary read or write access to authorize.conf and remov...
by 10306629 New Member in Splunk Enterprise Security 11-27-2017
0 4
0
4
soumyasaha2506
I am quite new to ES, although i have an good understanding of data models and other Splunk commands, i am unable to ...
by soumyasaha2506 Loves-to-Learn in Splunk Enterprise Security 11-21-2017
0 1
0
1
test_qweqwe
How to change this search to show Unsuccessful/Failed Windows Updates? sourcetype=WinEventLog:System EventCode=19...
by test_qweqwe Builder in Splunk Enterprise Security 11-21-2017
0 2
0
2
rohansecadvbot
Hi I am trying to create add-ons for splunk enterprise security. is there a developer version of the app , with sampl...
by rohansecadvbot Explorer in Splunk Enterprise Security 11-17-2017
0 2
0
2
brianyaucy
Hi all! I have just started working on Splunk ES. However I found that when turned on the correlation rule below, th...
by brianyaucy New Member in Splunk Enterprise Security 11-16-2017
0 5
0
5
test_qweqwe
I will try again, but with correct tags of my question. Today I tried many times fix it and zero results. https://p...
by test_qweqwe Builder in Splunk Enterprise Security 11-15-2017
0 5
0
5
sbattista09
in the Top 20 Memory-Consuming Searches dashboard in the DMC OR DM OR whatever its called nowadays i am seeing the us...
by sbattista09 Contributor in Splunk Enterprise Security 11-14-2017
0 1
0
1
test_qweqwe
I have this search: | metadata type=hosts | lookup critical_systems Host_name as host OUTPUT Host_name as host | sear...
by test_qweqwe Builder in Splunk Enterprise Security 11-14-2017
0 5
0
5
test_qweqwe
Hello my little friends!  In your opinion what correlation searches must have SOC?
by test_qweqwe Builder in Splunk Enterprise Security 11-14-2017
0 3
0
3
deepu123
I am using search head cluster and trying to create a correlation search by selecting application context as "DA-ESS-...
by deepu123 Explorer in Splunk Enterprise Security 11-12-2017
0 1
0
1
responsys_cm
I have a customer with a very unique network environment. They will have multiple ES clusters worldwide. The only w...
by responsys_cm Builder in Splunk Enterprise Security 11-10-2017
0 5
0
5
kannanmallan
We are on Splunk Cloud 6.4. We have Splunk Enterprise Security too. FireEye App for Splunk Enterprise v3 (ver 3.0....
by kannanmallan New Member in Splunk Enterprise Security 11-10-2017
0 3
0
3
JeffBothel
I am looking to get a ratio in something akin to the following method but this is throwing errors from Splunk ES: ev...
by JeffBothel Explorer in Splunk Enterprise Security 11-09-2017
0 1
0
1
MonkeyK
pancontentpack is supposed to get app and threat metadata from Panorama. I noticed that pancontentpack is only part ...
by MonkeyK Builder in Splunk Enterprise Security 11-07-2017
1 2
1
2
AshTillman11
I am seeing a number of events for abnormally high number of HTTP POST requests in our enterprise security incident r...
by AshTillman11 Engager in Splunk Enterprise Security 11-07-2017
1 2
1
2
thomas_porter
I upgraded the ES app from 4.5 to 4.7. I work on a closed system so I do not make use of the Threat Intel downloads....
by thomas_porter Explorer in Splunk Enterprise Security 11-07-2017
1 7
1
7
samhodgson
Hi All, I've just got Enterprise Security configured and im now trying to reduce the amount of false alarms created....
by samhodgson Path Finder in Splunk Enterprise Security 11-07-2017
2 3
2
3
sumitkathpal
Hi All, I just found that each logs of windows AD get tagged to alert data model, When i accelerate the data model f...
by sumitkathpal Explorer in Splunk Enterprise Security 11-07-2017
0 1
0
1
dsrvern
Hi, I'm using Splunk 6.6.3 with the Enterprise Security app, with access only to the web interface. I have two inde...
by dsrvern Explorer in Splunk Enterprise Security 11-06-2017
0 3
0
3
thambisetty
Hi, I have created correlation search and added Run a script adaptive response and notable adaptive response. I could...
by SplunkTrust SplunkTrust in Splunk Enterprise Security 11-06-2017
0 1
0
1
test_qweqwe
Hello all! What should I do or what should I know, (maybe some tricks or magic) if I need to quickly rewrite my searc...
by test_qweqwe Builder in Splunk Enterprise Security 11-02-2017
0 1
0
1
traxxasbreaker
I have an instance where I want to keep data model accelerations disabled but they seem to keep turning back on if I ...
by traxxasbreaker Communicator in Splunk Enterprise Security 10-30-2017
2 3
2
3
gerrydevenney
I have a 50GB Splunk licence and equivalent 50GB ES licence. I have been asked to install a 25GB ES licence in prepar...
by gerrydevenney Engager in Splunk Enterprise Security 10-30-2017
0 3
0
3
laleger
Is there any way to view actual contents of a threatlist via REST? I've found references to: | rest /services/data/t...
by laleger Explorer in Splunk Enterprise Security 10-28-2017
1 2
1
2
Get Updates on the Splunk Community!

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...

Recap | Agentic Operations Start with Context: Build the Right Data Foundation

Agentic Operations Start with Context: Build the Right Data Foundation   By Courtney Wright, Product Marketing ...

Recap | Assisted, Augmented or Agentic? Choose Your Splunk Starting Point

Assisted, Augmented or Agentic? Choose Your Splunk Starting Point   By Courtney Wright, Product Marketing ...