Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
colinjmchugo
I have a weighted score for repeat offenders using the following formula | table _time id priority.name username hos...
by colinjmchugo Explorer in Splunk Enterprise Security 09-07-2017
0 5
0
5
sumanssah
Hello, I am trying to create an Splunk query to get common username from 2 different sourcetype : 1st Sourcetype : ...
by sumanssah Communicator in Splunk Enterprise Security 09-05-2017
0 1
0
1
vanderaj2
Hey Splunkers, I'd like to assign an owner to some events appearing in the 'Incident Review" dashboard in the Enterp...
by vanderaj2 Path Finder in Splunk Enterprise Security 08-30-2017
1 3
1
3
guarisma
The Cisco ACI Add-on for Splunk Enterprise provides these source types: cisco:apic:health cisco:apic:stats cisco:api...
by guarisma Contributor in Splunk Enterprise Security 08-29-2017
0 2
0
2
Skins
IF an error is made when creating a correlation search - like using the wrong app context, and you'd like to remove t...
by Skins Path Finder in Splunk Enterprise Security 08-29-2017
1 1
1
1
JoeBlake
Can I combine enterprise security 3.3.0 with PCI 2.1.1 AND all of my other non CIM compliant apps into one big search...
by JoeBlake Engager in Splunk Enterprise Security 08-29-2017
3 4
3
4
yashwanth_g_pra
Hi, I wanted to create a user account having only access to ES-APP and within which he needs to have access to only ...
by yashwanth_g_pra Observer in Splunk Enterprise Security 08-25-2017
0 2
0
2
cjsweeney1
New Cisco security suite installed on the enterprise security server- i am see a 500 internal server error when atte...
by cjsweeney1 Explorer in Splunk Enterprise Security 08-23-2017
0 3
0
3
khagan
I've written some Correlation Searches in Enterprise Security and saved them in a custom app: "SA-Custom". I've chose...
by khagan Path Finder in Splunk Enterprise Security 08-23-2017
0 1
0
1
jdeer0618
There is a lookup in the SA-Utils app called "cron_schedule_map.csv" and I was wondering if any one out there knows h...
by jdeer0618 Explorer in Splunk Enterprise Security 08-22-2017
0 2
0
2
sumitkathpal
Hi All, I just installed the Custom Cluster Map Visualization APP ,APP is working in search and reporting but not wo...
by sumitkathpal Explorer in Splunk Enterprise Security 08-22-2017
0 2
0
2
mdessus_splunk
For the ones who use the Unix addon for extracting authentication events for Enterprise Security, and some events are...
by mdessus_splunk Splunk Employee Splunk Employee in Splunk Enterprise Security 08-18-2017
1 2
1
2
shubham87
I am in process of Splunk Enterprise Security deployment. While deployment of Add-ons to my indexers, documentation s...
by shubham87 Explorer in Splunk Enterprise Security 08-16-2017
0 3
0
3
shubham87
I have recently deployed Splunk Enterprise Security (ES) on one of our Search Heads. While installing, it could not p...
by shubham87 Explorer in Splunk Enterprise Security 08-15-2017
0 1
0
1
joshuamillikan
So having an issue with extreme search. I have a DD context generated for users sending emails based off their identi...
by joshuamillikan New Member in Splunk Enterprise Security 08-14-2017
0 3
0
3
R_B
Hello Splunk community, I am having a problem with Enterprise Security. All of the threat intelligences are not able...
by R_B Path Finder in Splunk Enterprise Security 08-11-2017
0 3
0
3
lakshman239
Greetings we have the following versions : Splunk 6.5.2/ES 4.5.0/CIM 4.6.0 When we use the macro on its own in the...
by lakshman239 Influencer in Splunk Enterprise Security 08-09-2017
0 1
0
1
shubham87
Hi, We are planning to use TCP syslog to send logs from networks devices to heavy forwarders and from there to index...
by shubham87 Explorer in Splunk Enterprise Security 08-09-2017
0 2
0
2
doodoodonk
I am trying to search the ip_intel kvstore for threat intelligence for an IP that I know is already there. I'm just ...
by doodoodonk Engager in Splunk Enterprise Security 08-08-2017
0 2
0
2
asimagu
This particular data model (Risk Analysis) that comes with Splunk Enterprise Security is failing to build due to a ca...
by asimagu Builder in Splunk Enterprise Security 08-07-2017
0 8
0
8
rmf185039
Hi everyone! I attempted to follow the other "Problems starting the eStreamer client" post but was unable to get it ...
by rmf185039 New Member in Splunk Enterprise Security 08-02-2017
0 3
0
3
vanderhoff
In Splunk Enterprise Security, the geographically improbable login correlation fires when users on our network transi...
by vanderhoff Explorer in Splunk Enterprise Security 07-23-2017
0 3
0
3
asimagu
Hi folks We upgraded Enterprise Security to 4.7.1 and we are getting the following errors in the UI: A threat intel...
by asimagu Builder in Splunk Enterprise Security 07-19-2017
0 1
0
1
kiran331
Hi is it possible to use 2 Splunk Enterprise Security apps on 2 stand alone search heads with same Indexer cluster?...
by kiran331 Builder in Splunk Enterprise Security 07-17-2017
0 7
0
7
jmaldonadojha
Good day, We are running Splunk Enterprise 6.6.0 with Splunk Enterprise Security distributed within several datacent...
by jmaldonadojha New Member in Splunk Enterprise Security 07-17-2017
0 1
0
1
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors