Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
leyip94105
Does anyone know if Splunk Enterprise Security supports Active Directory (or LDAP) for authentication, version 2008-R...
by leyip94105 New Member in Splunk Enterprise Security 02-03-2016
0 2
0
2
Abdeslem
hello , We want to add our Mcafee Firwall logs into splunk (ES) using syslog. which format is used by Splunk Add-o...
by Abdeslem New Member in Splunk Enterprise Security 02-01-2016
0 1
0
1
klawman
I'm working with Splunk Enterprise Security and I'm trying to build/refine correlations against the Network Traffic D...
by klawman Explorer in Splunk Enterprise Security 01-26-2016
1 4
1
4
saurabh_tek
Hello Dev Team, We are trying to receive logs from Riverbed CX-3070 Wan optimizer device into Splunk. In the rive...
by saurabh_tek Communicator in Splunk Enterprise Security 01-26-2016
0 1
0
1
phoenixdigital
Hi All, Just getting the community consensus here. Cisco ASA log events for Built and Teardown essentially contain t...
by phoenixdigital Builder in Splunk Enterprise Security 01-24-2016
0 1
0
1
AndySplunks
Has anyone ever tried updating the Incident Review Audit Dashboard in Splunk ES to include a timepicker? I can't see...
by AndySplunks Communicator in Splunk Enterprise Security 01-22-2016
0 2
0
2
bohanlon_splunk
In Enterprise Security, the Threat Intelligence Audit dashboard is not displaying properly. The _time and run_duratio...
by bohanlon_splunk Splunk Employee Splunk Employee in Splunk Enterprise Security 01-21-2016
0 2
0
2
vaibhavladani
Can any one help me in generating a lookup to dynamically add the Active Directory to the Splunk Enterprise Security...
by vaibhavladani Explorer in Splunk Enterprise Security 01-21-2016
0 3
0
3
mpuckettsc
I'm working with the Splunk Enterprise Security demo. Is there a way to reset it / delete all the data that it starts...
by mpuckettsc Explorer in Splunk Enterprise Security 01-20-2016
0 2
0
2
michael_lee
So we have various types of logs that Splunk collects. E.g. Windows events, web server logs, syslogs, cisco switches ...
by michael_lee Path Finder in Splunk Enterprise Security 01-19-2016
0 2
0
2
silasbarnesva
Hi all, Just upgraded Enterprise Security 3.0.1 to 4.0.1, all went well with the exception of one outstanding item. ...
by silasbarnesva Explorer in Splunk Enterprise Security 01-14-2016
0 1
0
1
tattersp
I have one search head and 3 indexers consuming about 50gb of data a day. All servers are running Splunk 6.3.1. The...
by tattersp Explorer in Splunk Enterprise Security 01-14-2016
0 4
0
4
srunyon
I added several objects to the "Vulnerabilities" data model. After that the Enterprise Security /Security Domains/Ne...
by srunyon New Member in Splunk Enterprise Security 01-13-2016
0 2
0
2
panovattack
Is there a way to accept a JSON as a threat intelligence download? I have a threat intelligence vendor that only pro...
by panovattack Communicator in Splunk Enterprise Security 01-07-2016
2 3
2
3
milesbrennan
We run a few Exchange servers and we need to collect logs for our Splunk Enterprise Security Suite, however, there ar...
by milesbrennan Path Finder in Splunk Enterprise Security 01-06-2016
0 3
0
3
martin_mueller
Using ESS 3.1.1 on Splunk 6.1.4, I can create a correlation search with an Umlaut in its name, such as "my cörrelatio...
by SplunkTrust SplunkTrust in Splunk Enterprise Security 01-04-2016
0 1
0
1
gary_richardson
Hello! Hope someone can assist. The search: | datamodel "Intrusion_Detection" "Network_IDS_Attacks" search | whe...
by gary_richardson Path Finder in Splunk Enterprise Security 01-04-2016
0 3
0
3
dirkmeeuwsen
We are looking to trigger a notable event when a series of events happen in a short period of time and in a specific ...
by dirkmeeuwsen Explorer in Splunk Enterprise Security 01-03-2016
1 1
1
1
cdev24
Hi Experts, I need your help to create query to show output when a system is infected with any malware\virus (Source...
by cdev24 New Member in Splunk Enterprise Security 12-30-2015
0 2
0
2
support0
Hello, On a search head cluster of 3 members with Splunk Enterprise Security, search results match exactly with all...
by support0 Path Finder in Splunk Enterprise Security 12-29-2015
1 3
1
3
jackshultz
I start a new position as a Cyber Security Engineer in the next couple of weeks and I have to learn as much about Spl...
by jackshultz New Member in Splunk Enterprise Security 12-28-2015
0 7
0
7
some_guy
Having an issue within Splunk ES Incident Review. The option to suppress events from most correlation searches work...
by some_guy Path Finder in Splunk Enterprise Security 12-22-2015
1 4
1
4
wtaylor149
I'm trying to setup a search to alert in ES when F5 LB is down for more than 15 minutes. The F5 LB only sends messag...
by wtaylor149 Explorer in Splunk Enterprise Security 12-19-2015
0 1
0
1
weicai88
Hi Everyone: I keep getting this error on my 3 Enterprise Security search heads: msg="A lookup table used in a CIDR...
by weicai88 Path Finder in Splunk Enterprise Security 12-18-2015
0 5
0
5
coleman07
Apache log data has out of the box sourcetypes, but no tag file to associate a tag of web to Apache log entries and I...
by coleman07 Path Finder in Splunk Enterprise Security 12-17-2015
0 2
0
2
Get Updates on the Splunk Community!

Splunk Cloud Application Management in Terraform

Now On-Demand   We’re diving into how you can bring Infrastructure as Code (IaC) principles to your Splunk ...

What's New in Splunk Enterprise Security (ES) 8.6

Purpose-Built AI Agents for the Agentic SOC  Splunk Enterprise Security 8.6 expands AI in Security with ...

From Raw Data to Executive-Ready Stories, Faster

Build Data Stories for Every Audience  A dashboard is rarely just a dashboard. It might be the view an ...