| Splunk Enterprise version is 6.5.2 kvstore correlationsearches_lookup is defined in app SA-ThreatIntelligence (versi... by ernieyee New Member in Splunk Enterprise Security 03-19-2017 0 2 | 0 | 2 | ||
| Does anyone have any advice on how to use Splunk's pre-canned correlation searches within Enterprise Security and hav... by tyrone_osilesi7 Explorer in Splunk Enterprise Security 03-17-2017 0 3 | 0 | 3 | ||
| All, So we have Splunk Enterprise Security (ES) working. Some of the dashboards are pretty nifty and we're thinking... by daniel333 Builder in Splunk Enterprise Security 03-17-2017 1 2 | 1 | 2 | ||
| I have an app installed from Splunkbase, which has custom search command defined in it. I've set the commands to be g... by szabados Communicator in Splunk Enterprise Security 03-14-2017 0 6 | 0 | 6 | ||
| I am very new using Extreme Searches. I have used the extreme search example that is displayed on the page in Splunk ... by mtaylor78 Engager in Splunk Enterprise Security 03-12-2017 0 3 | 0 | 3 | ||
| As I am fairly new to SHC, I seem to be getting the same message in ES when attempting to edit/view > Configure > Dat... by brian1_tate Path Finder in Splunk Enterprise Security 03-11-2017 0 2 | 0 | 2 | ||
| One of my servers is skipping a lot of accelerated searches, like 80% per each hour. I've got Splunk Enterprise Secur... by manderson7 Contributor in Splunk Enterprise Security 03-11-2017 2 2 | 2 | 2 | ||
| Hi, We use Linux Auditd app in our environment in conjunction with Splunk Enterprise Security (ES). Is there a way t... by att35 Builder in Splunk Enterprise Security 03-11-2017 1 1 | 1 | 1 | ||
| I have populated identities.csv on Splunk Enterprise Security and enabled the alert of "Activity from an expired iden... by andresito123 Communicator in Splunk Enterprise Security 03-09-2017 0 1 | 0 | 1 | ||
| Hi, I received this messages error : The correlation search XXXX in app "SplunkEnterpriseSecuritySuite" has no corre... by dellytaniasetia Explorer in Splunk Enterprise Security 03-03-2017 0 1 | 0 | 1 | ||
| Hi I keep receiving this error message from Splunk Enterprise Security (ES) on my custom python application, though ... by dellytaniasetia Explorer in Splunk Enterprise Security 03-02-2017 0 3 | 0 | 3 | ||
| Hello Splunk experts, Stuck trying to get something working and hoping one of you experts can point me in the right ... by splunker1981 Path Finder in Splunk Enterprise Security 03-01-2017 0 4 | 0 | 4 | ||
| Hi Folks, We are working on getting our Splunk Enterprise Security environment working properly and have it mostly s... by tryan65 Explorer in Splunk Enterprise Security 02-28-2017 0 5 | 0 | 5 | ||
| When using enterprise security protocol intelligence dashboards, how do you build a complete email transaction log (e... by panovattack Communicator in Splunk Enterprise Security 02-27-2017 0 2 | 0 | 2 | ||
| Can you provide a function which returns a string in an if statement? For example: if(src=="-" OR src=="127.0.0.1",... by panovattack Communicator in Splunk Enterprise Security 02-26-2017 0 2 | 0 | 2 | ||
| If an analyst has added a notable event to an investigation, how does another analyst open that notable event to revi... by panovattack Communicator in Splunk Enterprise Security 02-26-2017 0 4 | 0 | 4 | ||
| Is there a way to use lookups to add threat intelligence to the non-network based intelligence stores, such as file_... by panovattack Communicator in Splunk Enterprise Security 02-26-2017 0 3 | 0 | 3 | ||
| I have logs coming from different sources like juniper IDS, cisco firewall, bluecoat proxy, nessus etc. Currently I h... by anchalsingh Explorer in Splunk Enterprise Security 02-24-2017 0 3 | 0 | 3 | ||
| Hi Folks, I'm indexing log events en mass... and I know that I have events that always occur together and within th... by RocIngersol Explorer in Splunk Enterprise Security 02-22-2017 0 9 | 0 | 9 | ||
| Hi I'm trying to create a Identity Lookup for Splunk Enterprise Security. I have a users from Group and OU's which h... by kiran331 Builder in Splunk Enterprise Security 02-19-2017 0 2 | 0 | 2 | ||
| Incident review is not working after Splunk ESS 4.1.1 and CIM Upgrade. Also checked for data sources and their resp... by splunkrajkrk Explorer in Splunk Enterprise Security 02-17-2017 0 3 | 0 | 3 | ||
| We would like to add domains to the current threat list. I would think I could add to local_intel_domain or local_in... by john_glasscock Path Finder in Splunk Enterprise Security 02-13-2017 0 3 | 0 | 3 | ||
| Hi. Does anyone know what "Time" is referring to from "Incident Review" from Splunk Enterprise Security (see image b... by splunkrocks2014 Communicator in Splunk Enterprise Security 02-11-2017 0 2 | 0 | 2 | ||
| What is the best way for Enterprise Security to handle assets that are assigned DHCP addresses? Obviously the MAC ad... by responsys_cm Builder in Splunk Enterprise Security 02-11-2017 0 3 | 0 | 3 | ||
| I am trying to assign custom tags to notable events so that they can be triaged by certain analysts, i.e., tier 1. I ... by ErraticIncome93 Explorer in Splunk Enterprise Security 02-09-2017 1 2 | 1 | 2 |