Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
fairje
I am doing an upgrade of Enterprise Security from 3.3.1 to 4.0 through the GUI. I installed the app by providing it t...
by fairje Communicator in Splunk Enterprise Security 06-23-2016
0 10
0
10
gary_richardson
Hello In Enterprise Security, there is the option to run a script as a follow on action to a notable event. Is it po...
by gary_richardson Path Finder in Splunk Enterprise Security 06-20-2016
0 3
0
3
j4adam
Hello everyone, There is extensive documentation on what fields need to exist in order for a data source to fit into...
by j4adam Communicator in Splunk Enterprise Security 06-13-2016
1 2
1
2
att35
Hi, We have Linux Audit log data coming in Via OSSEC into Splunk. For this data, source is set to /var/ossec/logs/al...
by att35 Builder in Splunk Enterprise Security 06-08-2016
0 11
0
11
splunk_cv
Hi all, I wrote this search that shows me when certain SSIDs are matched. sourcetype=rogap SSID="*skynet*" OR SSID...
by splunk_cv Explorer in Splunk Enterprise Security 06-03-2016
0 5
0
5
trross33
After configuring the proxy settings for downloading the Splunk for Enterprise Security Intelligence Source data, I a...
by trross33 Path Finder in Splunk Enterprise Security 06-03-2016
0 1
0
1
echojacques
So this is the pre-configured correlation search called "substantial increase in port activity". I'd like to tweak i...
by echojacques Builder in Splunk Enterprise Security 06-02-2016
0 5
0
5
dragoslungu
Is there anything different when running a lookup on data returned by a pivot compared to the same lookup running on ...
by dragoslungu Explorer in Splunk Enterprise Security 05-25-2016
4 1
4
1
evelenke
Hi, Splunkers We have a single instance as an Indexer, Search head, and Splunk Enterprise Security (32Gb RAM,16 vCPU...
by evelenke Contributor in Splunk Enterprise Security 05-24-2016
1 4
1
4
andresito123
I get this error every hour at my installation: msg="A script exited abnormally" input="./bin/scripted_inputs/deplo...
by andresito123 Communicator in Splunk Enterprise Security 05-24-2016
0 2
0
2
sheamus69
Hi, I'm in the process of tuning our risk scores, as applied to objects (users or assets) from a correlation search....
by sheamus69 Communicator in Splunk Enterprise Security 05-20-2016
0 3
0
3
domenico_perre
Hi All, I am just posting a solution to an issue I have had with two upgrades for Splunk Enterprise Security. First...
by domenico_perre Path Finder in Splunk Enterprise Security 05-12-2016
0 1
0
1
hemendralodhi
Hello, I now have fairly good experience with Splunk and want to learn more about SIEM but not sure where to start. ...
by hemendralodhi Contributor in Splunk Enterprise Security 05-09-2016
0 2
0
2
splunker1981
Hello Splunkers, Can someone provide some guidance on what is the best or recommended method of adding context to as...
by splunker1981 Path Finder in Splunk Enterprise Security 05-08-2016
0 2
0
2
tsidie
Hello Splunk Answers! I'm relatively new to Splunk - pardon if this is a very basic question. I've looked through pr...
by tsidie Engager in Splunk Enterprise Security 05-04-2016
0 2
0
2
chrishatfield21
I have Splunk Enterprise 6.1, I've had the same issue on 6.0, and Enterprise Security 3.0 running. I pull in a dataso...
by chrishatfield21 Path Finder in Splunk Enterprise Security 04-29-2016
0 1
0
1
otan1010
Hi, Is Splunk Enterprise Security and Splunk User Behavior Analytics (Splunk UBA) totally independent apps? Do they...
by otan1010 Explorer in Splunk Enterprise Security 04-25-2016
1 1
1
1
joshfu
We've provided some background info to go with the questions as they relate to the Splunk Enterprise Security 4.x app...
by joshfu New Member in Splunk Enterprise Security 04-22-2016
0 3
0
3
mvrider
Hi, Does anyone in the community have test data that can fire off various Correlation Searches for Notable Events in...
by mvrider Engager in Splunk Enterprise Security 04-21-2016
1 1
1
1
Fraankiiie
The treat activity dashboard won't populate in the Splunk Enterprise Security app, although other dashboards (not all...
by Fraankiiie Engager in Splunk Enterprise Security 04-21-2016
0 7
0
7
neelamsantosh
I have recurring warnings in splunkd logs with multi-line header is missing matching quotation, or could not parse C...
by neelamsantosh Path Finder in Splunk Enterprise Security 04-19-2016
0 4
0
4
ryanoconnor
Should the Splunk App for ES Health Check be installed prior to Splunk Enterprise Security being installed? Can it ...
by ryanoconnor Builder in Splunk Enterprise Security 04-15-2016
0 1
0
1
johnmccash
I'm running Splunk Enterprise Security 4.0.1, and trying to import and match against Observables defined using Cybox ...
by johnmccash Explorer in Splunk Enterprise Security 04-15-2016
1 5
1
5
ccrider
I'm doing research inside of Splunk Enterprise Security, and I'm tagging events into the timeline. I've gone into the...
by ccrider New Member in Splunk Enterprise Security 04-14-2016
0 2
0
2
rahul130191
Is it possible to automate assignment of notable events to groups? For example, if a new notable event is triggered,...
by rahul130191 New Member in Splunk Enterprise Security 04-14-2016
0 1
0
1
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...
Top Solution Authors