Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
gerrydevenney
I have a 50GB Splunk licence and equivalent 50GB ES licence. I have been asked to install a 25GB ES licence in prepar...
by gerrydevenney Engager in Splunk Enterprise Security 10-30-2017
0 3
0
3
laleger
Is there any way to view actual contents of a threatlist via REST? I've found references to: | rest /services/data/t...
by laleger Explorer in Splunk Enterprise Security 10-28-2017
1 2
1
2
att35
Hi, When I search all indexed data against "Intrusion Detection" data model from Search & reporting app's context, S...
by att35 Builder in Splunk Enterprise Security 10-26-2017
0 7
0
7
tiagofbmm
Hi Can ES 4.7 be installed on a Windows SH? I know the documentation excludes ES with SHC on Windows, but it does no...
by tiagofbmm Influencer in Splunk Enterprise Security 10-25-2017
0 1
0
1
proletariat99
I tried $SPLUNK_HOME$/bin/splunk remove app SplunkEnterpriseSecuritySuite and it tells me "app doesn't exist" -- It d...
by proletariat99 Communicator in Splunk Enterprise Security 10-24-2017
0 5
0
5
Splunker6789
uninstall Splunk Enterprise Security Suite?
by Splunker6789 Explorer in Splunk Enterprise Security 10-23-2017
1 4
1
4
test_qweqwe
We have this config: [threatlist://ransomware_ip_blocklist] delim_regex = : description = abuse.ch Ransomware Bloc...
by test_qweqwe Builder in Splunk Enterprise Security 10-23-2017
0 1
0
1
donaldwayne1975
Pondering if the prohibited_traffic.csv lookup used by SA-NetworkProtection in Enterprise Security could be updated t...
by donaldwayne1975 Path Finder in Splunk Enterprise Security 10-21-2017
0 1
0
1
rbacker527
If I have a notable event is there a way within incident review to tag the user with watchlist?
by rbacker527 Engager in Splunk Enterprise Security 10-20-2017
0 1
0
1
kausar
I am looking for advices on how to plan the backup and storage of "My Investigations" data in the Splunk Enterprise S...
by kausar Path Finder in Splunk Enterprise Security 10-19-2017
0 3
0
3
test_qweqwe
It's impossible to detect WannaCry by app ES Content Updates? Someone have experience in this? app: https://splunkba...
by test_qweqwe Builder in Splunk Enterprise Security 10-19-2017
0 2
0
2
GenericSplunkUs
Hello All, I'm looking to find a history of what notables have been suppressed after the suppression has expired. I'...
by GenericSplunkUs Path Finder in Splunk Enterprise Security 10-18-2017
0 1
0
1
gopmister
I am running a ESS Correlation search in App Context Enterprise Security. I verified the lookup and it exists in the...
by gopmister Explorer in Splunk Enterprise Security 10-16-2017
0 3
0
3
panovattack
I have installed extra visualization (e.g. Sankey). The visualization option is available in the search app and the ...
by panovattack Communicator in Splunk Enterprise Security 10-15-2017
0 1
0
1
echojacques
This correlation search detects a "substantial increase in port activity" and it works well. How can I tune/modify i...
by echojacques Builder in Splunk Enterprise Security 10-12-2017
0 6
0
6
dellytaniasetia
Hi Is it possible to clone/duplicate Incident Review in the Splunk Enterprise Security app? I would like to create 2...
by dellytaniasetia Explorer in Splunk Enterprise Security 10-10-2017
0 6
0
6
MonkeyK
Are there best practices when mapping PaloAlto firewall logs to CIM datamodels? One think that I noticed is that Netw...
by MonkeyK Builder in Splunk Enterprise Security 10-10-2017
1 2
1
2
tracegordon
In an Enterprise Security Correlation Search I have a report that emails out when an email address is seen across mul...
by tracegordon Engager in Splunk Enterprise Security 10-10-2017
1 1
1
1
rdjoraev_splunk
There many reports of high CPU or memory utilization on the indexers after upgrading Spunk Enterprise Security (ES) t...
by rdjoraev_splunk Splunk Employee Splunk Employee in Splunk Enterprise Security 10-06-2017
0 2
0
2
support0
Hi there, I have deployed Splunk Stream on a distributed environment. SH ES > Stream App + Stream TA IDX > Stream ...
by support0 Path Finder in Splunk Enterprise Security 10-05-2017
0 2
0
2
sumanssah
Hi, I am creating an dashboard and want to know, if we have any possibility to add data manually to sourcetype. Exa...
by sumanssah Communicator in Splunk Enterprise Security 10-05-2017
0 2
0
2
MAMAOUI
Hi All I'm looking for informations or methods on integrating RMS (Rights Management service/Office365) into Splun...
by MAMAOUI Explorer in Splunk Enterprise Security 10-03-2017
0 1
0
1
wilhelmF
We just recently upgraded to the latest version of ES 4.7.2 from 4.5.2 However after upgrading the page content manag...
by wilhelmF Path Finder in Splunk Enterprise Security 10-01-2017
0 6
0
6
LukeMurphey
I want to add some fields to a data-model that comes with the Common Information Model app but I want to avoid rebuil...
by LukeMurphey Champion in Splunk Enterprise Security 09-29-2017
0 1
0
1
shandman
The last post I see on this subject is almost three years old. Does anyone know if there is a Tripwire TA that integr...
by shandman Path Finder in Splunk Enterprise Security 09-25-2017
0 2
0
2
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...