Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
luckymaddy
Hi All, I am new to Splunk. In my project we are using Splunk App for Enterprise security. I would like to know what...
by luckymaddy Explorer in Splunk Enterprise Security 04-27-2015
0 8
0
8
masiddiqu
Hi, I am trying to simulate a cluster environment for the Splunk App for Enterprise Security. The setup is: -Two I...
by masiddiqu Explorer in Splunk Enterprise Security 04-23-2015
0 3
0
3
georget
Hi, I've created a new Key Security Indicator for my app and have integrated it in the Security Posture dashboard of...
by georget Explorer in Splunk Enterprise Security 04-22-2015
0 3
0
3
bheemireddi
I have a scenario. The customer has two teams ABC, XYZ and they have their own Enterprise Security setup. each team h...
by bheemireddi Communicator in Splunk Enterprise Security 04-18-2015
1 1
1
1
Splunk_Bw
I have been assigned the task of deploying the Splunk App for Enterprise Security on Linux machines. Here is my requi...
by Splunk_Bw Explorer in Splunk Enterprise Security 04-16-2015
0 2
0
2
coleman07
The sample data which comes with the TA-sav add-on has its timestamp in a weird hexadecimal format. It looks like th...
by coleman07 Path Finder in Splunk Enterprise Security 04-09-2015
0 3
0
3
mcronkrite
Can you put in the url field of the threat list a domain value? For example, these were where domains were listed xx...
by mcronkrite Splunk Employee Splunk Employee in Splunk Enterprise Security 03-27-2015
0 1
0
1
tkopchak
Any time I load the debug/refresh endpoint, correlation searches stop running. Or, at least, they stop producing nota...
by SplunkTrust SplunkTrust in Splunk Enterprise Security 03-26-2015
0 1
0
1
jonathan_cooper
I'm working on tuning our data model accelerations and the first problem I'm running into is that they never finish. ...
by jonathan_cooper Communicator in Splunk Enterprise Security 03-26-2015
7 8
7
8
adsplunk1
Good afternoon. This is related to Enterprise Security 3.1.1 build 219910. Is it possible to allow a non-admin user...
by adsplunk1 New Member in Splunk Enterprise Security 03-18-2015
0 2
0
2
RiccardoV
Hi, I am using Splunk 6.2.2 and Enterprise Security 3.1.1. I have a bunch of threat lists (the actual URLs are looku...
by RiccardoV Communicator in Splunk Enterprise Security 03-18-2015
1 1
1
1
coolwater77
Can I create a security operations workflows using the ES app? For example, if I want a ticket to be opened in the ti...
by coolwater77 Explorer in Splunk Enterprise Security 03-15-2015
1 5
1
5
Chubbybunny
I've disabled the Google search feature in ./SA-ThreatIntelligence/local/workflow_actions.conf and confirmed it is no...
by Chubbybunny Splunk Employee Splunk Employee in Splunk Enterprise Security 03-11-2015
1 1
1
1
dschmidt_cfi
I realize this will be simple for someone with more experience than I have. Running 2 search heads, 2 indexers, manag...
by dschmidt_cfi Path Finder in Splunk Enterprise Security 03-11-2015
2 13
2
13
mcronkrite
Can you have multiple domain names on single url field? Or does every row have to have single domain name?
by mcronkrite Splunk Employee Splunk Employee in Splunk Enterprise Security 03-07-2015
0 4
0
4
john_miller1
I have been testing the Splunk Add-on for Nessus and want to start using the feature with fresh data. Is there a way...
by john_miller1 Explorer in Splunk Enterprise Security 03-03-2015
0 1
0
1
skathpal
Hello Everyone, I need to setup the email output action for ES APP correlation Searches , I have found that we cant ...
by skathpal Explorer in Splunk Enterprise Security 02-26-2015
0 1
0
1
mzorzi
According to the documentation for ES Asset management here: http://docs.splunk.com/Documentation/ES/3.2.1/User/Asse...
by mzorzi Splunk Employee Splunk Employee in Splunk Enterprise Security 02-26-2015
1 1
1
1
BenjaminWyatt
We recently upgraded our Enterprise Security instance to v3.0 from v2.4. After the upgrade, I noticed that Correlatio...
by BenjaminWyatt Communicator in Splunk Enterprise Security 02-25-2015
0 4
0
4
mcronkrite
0
1
RiccardoV
Hi, I have a question about custom threatlists in Splunk App for Enterprise Security. If I add a new custom threatli...
by RiccardoV Communicator in Splunk Enterprise Security 02-18-2015
0 3
0
3
RiccardoV
Hi guys, I am wondering if I could use a binary file with my own format as threat list in Splunk ES app. That file co...
by RiccardoV Communicator in Splunk Enterprise Security 02-18-2015
0 1
0
1
Alteek
Hi, I"m running the Enterprise Security app and I"m facing the following issue: Notable events or Incidents are cre...
by Alteek Explorer in Splunk Enterprise Security 02-17-2015
0 2
0
2
chris
I'm trying to integrate McAfee data into ES and I am having difficulties using the datamodel command. Why does this ...
by chris Motivator in Splunk Enterprise Security 02-16-2015
1 2
1
2
Splunker
Hi all, Have a 2 site distributed-architecture of Splunk, with 1 Search-Head in either site (and indexers and heavy-...
by Splunker Communicator in Splunk Enterprise Security 02-11-2015
0 2
0
2
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...
Top Solution Authors