Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
panovattack
I am looking for anyone who might know the appropriate BIND logging configuration to capture DNS replies so that we c...
by panovattack Communicator in Splunk Enterprise Security 04-14-2017
1 3
1
3
kkkelvinkk
Hi all, I am now researching Splunk Enterprise Security. From my understanding, it is an app with some dashboard, wh...
by kkkelvinkk New Member in Splunk Enterprise Security 04-13-2017
0 3
0
3
sriramcam
I just signed up to Splunk Enterprise Security (ES) sandbox but I do not see any links to create glass tables. Where ...
by sriramcam New Member in Splunk Enterprise Security 04-12-2017
0 1
0
1
abalogh_splunk
We have just upgraded Splunk Enterprise 6.4.1 / Splunk Enterprise Security 4.1.1 to Splunk Enterprise 6.5.2 with Sp...
by abalogh_splunk Splunk Employee Splunk Employee in Splunk Enterprise Security 04-10-2017
0 1
0
1
kkkelvinkk
Hi, I have installed a splunk enterprise trial and also requested Splunk Enterprise Security. I noticed that when I ...
by kkkelvinkk New Member in Splunk Enterprise Security 04-07-2017
0 2
0
2
RihabCH2
Hello , I have a distributed architecture of Splunk Search Head with Splunk Enterprise Security and an indexer . I g...
by RihabCH2 Engager in Splunk Enterprise Security 04-07-2017
0 6
0
6
asimagu
Hey gents My customer is asking me to create a new threat intelligence source in the Enterprise Security app (versio...
by asimagu Builder in Splunk Enterprise Security 04-07-2017
1 2
1
2
ctripod
Hi all, Are there any alternatives to domaintools whois API for Enterprise Security integration? A lot of customers...
by ctripod Explorer in Splunk Enterprise Security 04-06-2017
1 1
1
1
robertlight
I have created a Splunk app and am sending ajax request to it from the browser. The serverside python code will then...
by robertlight Path Finder in Splunk Enterprise Security 04-06-2017
1 8
1
8
szabados
In Enterprise Security, for a drill down action I want to use a field from the notable events, which can have multi v...
by szabados Communicator in Splunk Enterprise Security 04-06-2017
0 2
0
2
mbdiameth
I have no experience and I need to set up a SOC/NOC with Splunk. Thank you for andurstanding me and helping me.
by mbdiameth New Member in Splunk Enterprise Security 04-05-2017
0 6
0
6
mhoogenboom
Since upgrading Splunk to 6.5.2, in the Splunk Enterprise Security (ES) search page I get "TypeError: message is unde...
by mhoogenboom New Member in Splunk Enterprise Security 04-03-2017
0 4
0
4
lukedunzweiler
Having a hard time getting an alert that works with FortigateAR. We want to use FortigateAR to block SourceIP based ...
by lukedunzweiler Engager in Splunk Enterprise Security 03-28-2017
0 2
0
2
jwiedemann_splu
I know that it is possible to embed an Adaptive Response hyperlink into the next steps section of Splunk Enterprise S...
by jwiedemann_splu Splunk Employee Splunk Employee in Splunk Enterprise Security 03-27-2017
0 2
0
2
daniel333
All, Might just be lack of caffeine here. But I can't quite get this subsearch working. I have my assets.csv setu...
by daniel333 Builder in Splunk Enterprise Security 03-21-2017
0 1
0
1
cwilmoth
Does it make sense to turn data model acceleration on for the Incident Management data model (default summary range i...
by cwilmoth Path Finder in Splunk Enterprise Security 03-21-2017
0 6
0
6
gsopkoTC
Does the Splunk Add-on for Bit9 Carbon Black format the CB JSON md5 field to either Malware.file_hash or Email.file_h...
by gsopkoTC Path Finder in Splunk Enterprise Security 03-20-2017
0 2
0
2
ernieyee
Splunk Enterprise version is 6.5.2 kvstore correlationsearches_lookup is defined in app SA-ThreatIntelligence (versi...
by ernieyee New Member in Splunk Enterprise Security 03-19-2017
0 2
0
2
tyrone_osilesi7
Does anyone have any advice on how to use Splunk's pre-canned correlation searches within Enterprise Security and hav...
by tyrone_osilesi7 Explorer in Splunk Enterprise Security 03-17-2017
0 3
0
3
daniel333
All, So we have Splunk Enterprise Security (ES) working. Some of the dashboards are pretty nifty and we're thinking...
by daniel333 Builder in Splunk Enterprise Security 03-17-2017
1 2
1
2
szabados
I have an app installed from Splunkbase, which has custom search command defined in it. I've set the commands to be g...
by szabados Communicator in Splunk Enterprise Security 03-14-2017
0 6
0
6
mtaylor78
I am very new using Extreme Searches. I have used the extreme search example that is displayed on the page in Splunk ...
by mtaylor78 Engager in Splunk Enterprise Security 03-12-2017
0 3
0
3
brian1_tate
As I am fairly new to SHC, I seem to be getting the same message in ES when attempting to edit/view > Configure > Dat...
by brian1_tate Path Finder in Splunk Enterprise Security 03-11-2017
0 2
0
2
manderson7
One of my servers is skipping a lot of accelerated searches, like 80% per each hour. I've got Splunk Enterprise Secur...
by manderson7 Contributor in Splunk Enterprise Security 03-11-2017
2 2
2
2
att35
Hi, We use Linux Auditd app in our environment in conjunction with Splunk Enterprise Security (ES). Is there a way t...
by att35 Builder in Splunk Enterprise Security 03-11-2017
1 1
1
1
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...