Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
ernieyee
Splunk Enterprise version is 6.5.2 kvstore correlationsearches_lookup is defined in app SA-ThreatIntelligence (versi...
by ernieyee New Member in Splunk Enterprise Security 03-19-2017
0 2
0
2
tyrone_osilesi7
Does anyone have any advice on how to use Splunk's pre-canned correlation searches within Enterprise Security and hav...
by tyrone_osilesi7 Explorer in Splunk Enterprise Security 03-17-2017
0 3
0
3
daniel333
All, So we have Splunk Enterprise Security (ES) working. Some of the dashboards are pretty nifty and we're thinking...
by daniel333 Builder in Splunk Enterprise Security 03-17-2017
1 2
1
2
szabados
I have an app installed from Splunkbase, which has custom search command defined in it. I've set the commands to be g...
by szabados Communicator in Splunk Enterprise Security 03-14-2017
0 6
0
6
mtaylor78
I am very new using Extreme Searches. I have used the extreme search example that is displayed on the page in Splunk ...
by mtaylor78 Engager in Splunk Enterprise Security 03-12-2017
0 3
0
3
brian1_tate
As I am fairly new to SHC, I seem to be getting the same message in ES when attempting to edit/view > Configure > Dat...
by brian1_tate Path Finder in Splunk Enterprise Security 03-11-2017
0 2
0
2
manderson7
One of my servers is skipping a lot of accelerated searches, like 80% per each hour. I've got Splunk Enterprise Secur...
by manderson7 Contributor in Splunk Enterprise Security 03-11-2017
2 2
2
2
att35
Hi, We use Linux Auditd app in our environment in conjunction with Splunk Enterprise Security (ES). Is there a way t...
by att35 Builder in Splunk Enterprise Security 03-11-2017
1 1
1
1
andresito123
I have populated identities.csv on Splunk Enterprise Security and enabled the alert of "Activity from an expired iden...
by andresito123 Communicator in Splunk Enterprise Security 03-09-2017
0 1
0
1
dellytaniasetia
Hi, I received this messages error : The correlation search XXXX in app "SplunkEnterpriseSecuritySuite" has no corre...
by dellytaniasetia Explorer in Splunk Enterprise Security 03-03-2017
0 1
0
1
dellytaniasetia
Hi I keep receiving this error message from Splunk Enterprise Security (ES) on my custom python application, though ...
by dellytaniasetia Explorer in Splunk Enterprise Security 03-02-2017
0 3
0
3
splunker1981
Hello Splunk experts, Stuck trying to get something working and hoping one of you experts can point me in the right ...
by splunker1981 Path Finder in Splunk Enterprise Security 03-01-2017
0 4
0
4
tryan65
Hi Folks, We are working on getting our Splunk Enterprise Security environment working properly and have it mostly s...
by tryan65 Explorer in Splunk Enterprise Security 02-28-2017
0 5
0
5
panovattack
When using enterprise security protocol intelligence dashboards, how do you build a complete email transaction log (e...
by panovattack Communicator in Splunk Enterprise Security 02-27-2017
0 2
0
2
panovattack
Can you provide a function which returns a string in an if statement? For example: if(src=="-" OR src=="127.0.0.1",...
by panovattack Communicator in Splunk Enterprise Security 02-26-2017
0 2
0
2
panovattack
If an analyst has added a notable event to an investigation, how does another analyst open that notable event to revi...
by panovattack Communicator in Splunk Enterprise Security 02-26-2017
0 4
0
4
panovattack
Is there a way to use lookups to add threat intelligence to the non-network based intelligence stores, such as file_...
by panovattack Communicator in Splunk Enterprise Security 02-26-2017
0 3
0
3
anchalsingh
I have logs coming from different sources like juniper IDS, cisco firewall, bluecoat proxy, nessus etc. Currently I h...
by anchalsingh Explorer in Splunk Enterprise Security 02-24-2017
0 3
0
3
RocIngersol
Hi Folks, I'm indexing log events en mass... and I know that I have events that always occur together and within th...
by RocIngersol Explorer in Splunk Enterprise Security 02-22-2017
0 9
0
9
kiran331
Hi I'm trying to create a Identity Lookup for Splunk Enterprise Security. I have a users from Group and OU's which h...
by kiran331 Builder in Splunk Enterprise Security 02-19-2017
0 2
0
2
splunkrajkrk
Incident review is not working after Splunk ESS 4.1.1 and CIM Upgrade. Also checked for data sources and their resp...
by splunkrajkrk Explorer in Splunk Enterprise Security 02-17-2017
0 3
0
3
john_glasscock
We would like to add domains to the current threat list. I would think I could add to local_intel_domain or local_in...
by john_glasscock Path Finder in Splunk Enterprise Security 02-13-2017
0 3
0
3
splunkrocks2014
Hi. Does anyone know what "Time" is referring to from "Incident Review" from Splunk Enterprise Security (see image b...
by splunkrocks2014 Communicator in Splunk Enterprise Security 02-11-2017
0 2
0
2
responsys_cm
What is the best way for Enterprise Security to handle assets that are assigned DHCP addresses? Obviously the MAC ad...
by responsys_cm Builder in Splunk Enterprise Security 02-11-2017
0 3
0
3
ErraticIncome93
I am trying to assign custom tags to notable events so that they can be triaged by certain analysts, i.e., tier 1. I ...
by ErraticIncome93 Explorer in Splunk Enterprise Security 02-09-2017
1 2
1
2
Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

Federated Search for Dynamic Data Self Storage Is Now Generally Available on Splunk ...

 Splunk is excited to announce the General Availability of Federated Search for Dynamic Data Self Storage ...

Index This | What has many keys but can’t unlock a door?

July 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...