Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
panovattack
If an analyst has added a notable event to an investigation, how does another analyst open that notable event to revi...
by panovattack Communicator in Splunk Enterprise Security 02-26-2017
0 4
0
4
panovattack
Is there a way to use lookups to add threat intelligence to the non-network based intelligence stores, such as file_...
by panovattack Communicator in Splunk Enterprise Security 02-26-2017
0 3
0
3
anchalsingh
I have logs coming from different sources like juniper IDS, cisco firewall, bluecoat proxy, nessus etc. Currently I h...
by anchalsingh Explorer in Splunk Enterprise Security 02-24-2017
0 3
0
3
RocIngersol
Hi Folks, I'm indexing log events en mass... and I know that I have events that always occur together and within th...
by RocIngersol Explorer in Splunk Enterprise Security 02-22-2017
0 9
0
9
kiran331
Hi I'm trying to create a Identity Lookup for Splunk Enterprise Security. I have a users from Group and OU's which h...
by kiran331 Builder in Splunk Enterprise Security 02-19-2017
0 2
0
2
splunkrajkrk
Incident review is not working after Splunk ESS 4.1.1 and CIM Upgrade. Also checked for data sources and their resp...
by splunkrajkrk Explorer in Splunk Enterprise Security 02-17-2017
0 3
0
3
john_glasscock
We would like to add domains to the current threat list. I would think I could add to local_intel_domain or local_in...
by john_glasscock Path Finder in Splunk Enterprise Security 02-13-2017
0 3
0
3
splunkrocks2014
Hi. Does anyone know what "Time" is referring to from "Incident Review" from Splunk Enterprise Security (see image b...
by splunkrocks2014 Communicator in Splunk Enterprise Security 02-11-2017
0 2
0
2
responsys_cm
What is the best way for Enterprise Security to handle assets that are assigned DHCP addresses? Obviously the MAC ad...
by responsys_cm Builder in Splunk Enterprise Security 02-11-2017
0 3
0
3
ErraticIncome93
I am trying to assign custom tags to notable events so that they can be triaged by certain analysts, i.e., tier 1. I ...
by ErraticIncome93 Explorer in Splunk Enterprise Security 02-09-2017
1 2
1
2
season88481
Hi guys, Anyone ever seen this: When I load the Splunk page, the navigation bar at the top looks OK. Then I load t...
by season88481 Contributor in Splunk Enterprise Security 02-08-2017
0 6
0
6
paulstout
Is it possible to merge the notable events from Splunk IT Service Intelligence (ITSI) and Splunk Enterprise Security ...
by paulstout Path Finder in Splunk Enterprise Security 02-08-2017
0 3
0
3
jgbricker
Trying to figure out why the Splunk Enterprise Security App has a savedsearch and a correlation search for brute forc...
by jgbricker Contributor in Splunk Enterprise Security 02-08-2017
0 6
0
6
tyrone_osilesi7
Hi, I have a lookup file tracking IOCs from multiple sources. I'm looking for a way to take this list and ideally ge...
by tyrone_osilesi7 Explorer in Splunk Enterprise Security 02-08-2017
0 1
0
1
Rocky31
No new malware showing up in Malware center. We had no malware from last two weeks, any idea, i'm very new to Splunk
by Rocky31 Path Finder in Splunk Enterprise Security 02-07-2017
0 4
0
4
chiltonb
I have made a workflow action item that looks up details on an IP address when there is a threat hit. This works whe...
by chiltonb Explorer in Splunk Enterprise Security 02-07-2017
0 4
0
4
nandha_2
can i hold all the events which matched the correlation search in Splunk Enterprise Security, before it gets indexed ...
by nandha_2 Engager in Splunk Enterprise Security 02-04-2017
0 4
0
4
nandha_2
Hi there, I would like to add a custom pipeline before indexer pipe-line? Does Splunk provide the feasibility? Th...
by nandha_2 Engager in Splunk Enterprise Security 02-03-2017
0 4
0
4
nandha_2
I have configured "Correlation Search" and I would like to grab all the related events for that notable (by skipping ...
by nandha_2 Engager in Splunk Enterprise Security 02-03-2017
0 3
0
3
naqviah
I have been trying to configure the Linux Auditd app to get it 100% functioning. Some of the panes are working and so...
by naqviah Explorer in Splunk Enterprise Security 02-02-2017
0 2
0
2
LukeMurphey
After upgrading my ES installation to version 3.3.1, the Incident Review page fails to load. The Firefox console show...
by LukeMurphey Champion in Splunk Enterprise Security 02-02-2017
2 3
2
3
LukeMurphey
I have Splunk Enterprise Security and I want Incident Review to refresh itself automatically. What is the best way to...
by LukeMurphey Champion in Splunk Enterprise Security 02-02-2017
1 1
1
1
Rocky31
i want to see an event in incident review on admin activity, how to create a correlation search for, give me advice ...
by Rocky31 Path Finder in Splunk Enterprise Security 02-01-2017
0 9
0
9
mgrosholz
I know how to change the default time range in the search head but it only applies to the Search & Reporting app. Doe...
by mgrosholz Path Finder in Splunk Enterprise Security 01-31-2017
0 5
0
5
gordone
So, I am not clear whether this has been asked before, but I'll ask it directly. I want to present the results of my...
by gordone Explorer in Splunk Enterprise Security 01-25-2017
1 1
1
1
Get Updates on the Splunk Community!

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors