Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
droth333
In Splunk Enterprise Security (ES), we cannot save a correlation search as a user with ess_admin. This works if user...
by droth333 Explorer in Splunk Enterprise Security 12-16-2016
0 2
0
2
andygerber
My SOC wants a page showing all recent notables, and which ones were suppressed by the current suppression rules. Ob...
by andygerber Path Finder in Splunk Enterprise Security 12-15-2016
0 1
0
1
Monica7
Hi, I need some clarifications on Splunk Enterprise and Splunk Enterprise Security. I would like to implement SIEM ...
by Monica7 New Member in Splunk Enterprise Security 12-13-2016
0 8
0
8
bettymh
Hello everyone I'm using Splunk Enterprise Security, and at the first sight, I saw urgency which includes: "critical...
by bettymh New Member in Splunk Enterprise Security 12-12-2016
0 6
0
6
Lowell
Running into an issue with the "Substantial Increase In Port Activity" correlation search in ES. Essentially this se...
by Lowell Super Champion in Splunk Enterprise Security 12-11-2016
1 2
1
2
Lowell
Trying to get my head wrapped around this Extreme Search thing and I'm not finding any great (or well written) docs. ...
by Lowell Super Champion in Splunk Enterprise Security 12-11-2016
3 2
3
2
noybin
Can I install and use Extreme Search without Enterprise Seurity? If yes, where should be installed (Search Head, Ind...
by noybin Communicator in Splunk Enterprise Security 12-11-2016
1 10
1
10
jamesatwork703
On my 'Threat Activity Dashboard', I see a panel labeled 'Most Active Threat Collections', but the numbers don't seem...
by jamesatwork703 Engager in Splunk Enterprise Security 12-09-2016
0 3
0
3
nychawk
Hello; I am running Splunk Enterprise Security and would like to enable security events to trigger events in Service...
by nychawk Communicator in Splunk Enterprise Security 12-09-2016
0 6
0
6
sumitkathpal
Hi All, Here is the scenario: Currently we are using custom threat intelligence in Splunk Enterprise Security to do...
by sumitkathpal Explorer in Splunk Enterprise Security 12-08-2016
0 3
0
3
kiran331
HI I have to remove a user account in Splunk. What happens to the incidents closed or resolved by that user?
by kiran331 Builder in Splunk Enterprise Security 12-08-2016
0 1
0
1
ericlarsen
We just implemented Splunk Enterprise Security about a month ago. We're new to data models, acceleration, and any im...
by ericlarsen Path Finder in Splunk Enterprise Security 12-07-2016
0 3
0
3
pinVie
Hi all, So since today, I get the following error message in _internal (sourcetype splunk_web_service): "error:138...
by pinVie Path Finder in Splunk Enterprise Security 12-07-2016
1 1
1
1
dellytaniasetia
Hello, Anyone successfully implement search for 2 failed login followed by a successful login in Windows? Here is ...
by dellytaniasetia Explorer in Splunk Enterprise Security 12-06-2016
0 2
0
2
stmcmahon_splun
Hello Had someone ask: Extreme Search Visualization (XSV), is designed as a "helper" app for Scianta Analytics' Ext...
by stmcmahon_splun Splunk Employee Splunk Employee in Splunk Enterprise Security 12-06-2016
0 2
0
2
splunkrajkrk
Hi All , I am trying to get DNS data into Splunk Enterprise Security 4.5 we already have Windows Server DNS logs in ...
by splunkrajkrk Explorer in Splunk Enterprise Security 12-05-2016
0 5
0
5
TWiseOne
HI, I recently deployed Splunk Enterprise Security 4.5 into a Search Head Cluster and whenever I use the Splunk App ...
by TWiseOne Path Finder in Splunk Enterprise Security 12-02-2016
1 1
1
1
Monica7
I would like to know about the pricing details for Splunk Enterprise Security (Premium solution app). Can anyone shar...
by Monica7 New Member in Splunk Enterprise Security 12-01-2016
0 1
0
1
alandeandrea
We'd like to have clickable links in our notable event descriptions so that operations analysts can be directed to de...
by alandeandrea Explorer in Splunk Enterprise Security 11-30-2016
0 3
0
3
alevy
Hi There, I am working on an app and would like my data to be visible in the Splunk Enterprise Security dashboards. ...
by alevy Path Finder in Splunk Enterprise Security 11-29-2016
0 2
0
2
sphadnis
Hi - I see the app (Qualys VM App for Splunk Enterprise) description does not list Splunk 6.5.1 version as compatible...
by sphadnis Path Finder in Splunk Enterprise Security 11-28-2016
0 1
0
1
jamesatwork703
Other than the documentation I've read on the actual Splunk website, is there anything out there or does anybody have...
by jamesatwork703 Engager in Splunk Enterprise Security 11-28-2016
0 5
0
5
Monica7
Is it possible to use the Licensed version of the Splunk Enterprise Security on top of Splunk Light free trial versio...
by Monica7 New Member in Splunk Enterprise Security 11-25-2016
0 9
0
9
bradp1234
We have a Splunk ES user who has left and now their correlation searches are orphaned. I am aware of the feature to c...
by bradp1234 Path Finder in Splunk Enterprise Security 11-23-2016
0 1
0
1
jamesatwork703
Is there a way to remove threat intelligence feeds from the 'Threat Intelligence Downloads' section? I know I can dis...
by jamesatwork703 Engager in Splunk Enterprise Security 11-23-2016
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...
Top Solution Authors