Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
georget
Hi, I've created a new Key Security Indicator for my app and have integrated it in the Security Posture dashboard of...
by georget Explorer in Splunk Enterprise Security 04-22-2015
0 3
0
3
bheemireddi
I have a scenario. The customer has two teams ABC, XYZ and they have their own Enterprise Security setup. each team h...
by bheemireddi Communicator in Splunk Enterprise Security 04-18-2015
1 1
1
1
Splunk_Bw
I have been assigned the task of deploying the Splunk App for Enterprise Security on Linux machines. Here is my requi...
by Splunk_Bw Explorer in Splunk Enterprise Security 04-16-2015
0 2
0
2
coleman07
The sample data which comes with the TA-sav add-on has its timestamp in a weird hexadecimal format. It looks like th...
by coleman07 Path Finder in Splunk Enterprise Security 04-09-2015
0 3
0
3
mcronkrite
Can you put in the url field of the threat list a domain value? For example, these were where domains were listed xx...
by mcronkrite Splunk Employee Splunk Employee in Splunk Enterprise Security 03-27-2015
0 1
0
1
tkopchak
Any time I load the debug/refresh endpoint, correlation searches stop running. Or, at least, they stop producing nota...
by SplunkTrust SplunkTrust in Splunk Enterprise Security 03-26-2015
0 1
0
1
jonathan_cooper
I'm working on tuning our data model accelerations and the first problem I'm running into is that they never finish. ...
by jonathan_cooper Communicator in Splunk Enterprise Security 03-26-2015
7 8
7
8
adsplunk1
Good afternoon. This is related to Enterprise Security 3.1.1 build 219910. Is it possible to allow a non-admin user...
by adsplunk1 New Member in Splunk Enterprise Security 03-18-2015
0 2
0
2
RiccardoV
Hi, I am using Splunk 6.2.2 and Enterprise Security 3.1.1. I have a bunch of threat lists (the actual URLs are looku...
by RiccardoV Communicator in Splunk Enterprise Security 03-18-2015
1 1
1
1
coolwater77
Can I create a security operations workflows using the ES app? For example, if I want a ticket to be opened in the ti...
by coolwater77 Explorer in Splunk Enterprise Security 03-15-2015
1 5
1
5
Chubbybunny
I've disabled the Google search feature in ./SA-ThreatIntelligence/local/workflow_actions.conf and confirmed it is no...
by Chubbybunny Splunk Employee Splunk Employee in Splunk Enterprise Security 03-11-2015
1 1
1
1
dschmidt_cfi
I realize this will be simple for someone with more experience than I have. Running 2 search heads, 2 indexers, manag...
by dschmidt_cfi Path Finder in Splunk Enterprise Security 03-11-2015
2 13
2
13
mcronkrite
Can you have multiple domain names on single url field? Or does every row have to have single domain name?
by mcronkrite Splunk Employee Splunk Employee in Splunk Enterprise Security 03-07-2015
0 4
0
4
john_miller1
I have been testing the Splunk Add-on for Nessus and want to start using the feature with fresh data. Is there a way...
by john_miller1 Explorer in Splunk Enterprise Security 03-03-2015
0 1
0
1
skathpal
Hello Everyone, I need to setup the email output action for ES APP correlation Searches , I have found that we cant ...
by skathpal Explorer in Splunk Enterprise Security 02-26-2015
0 1
0
1
mzorzi
According to the documentation for ES Asset management here: http://docs.splunk.com/Documentation/ES/3.2.1/User/Asse...
by mzorzi Splunk Employee Splunk Employee in Splunk Enterprise Security 02-26-2015
1 1
1
1
BenjaminWyatt
We recently upgraded our Enterprise Security instance to v3.0 from v2.4. After the upgrade, I noticed that Correlatio...
by BenjaminWyatt Communicator in Splunk Enterprise Security 02-25-2015
0 4
0
4
mcronkrite
0
1
RiccardoV
Hi, I have a question about custom threatlists in Splunk App for Enterprise Security. If I add a new custom threatli...
by RiccardoV Communicator in Splunk Enterprise Security 02-18-2015
0 3
0
3
RiccardoV
Hi guys, I am wondering if I could use a binary file with my own format as threat list in Splunk ES app. That file co...
by RiccardoV Communicator in Splunk Enterprise Security 02-18-2015
0 1
0
1
Alteek
Hi, I"m running the Enterprise Security app and I"m facing the following issue: Notable events or Incidents are cre...
by Alteek Explorer in Splunk Enterprise Security 02-17-2015
0 2
0
2
chris
I'm trying to integrate McAfee data into ES and I am having difficulties using the datamodel command. Why does this ...
by chris Motivator in Splunk Enterprise Security 02-16-2015
1 2
1
2
Splunker
Hi all, Have a 2 site distributed-architecture of Splunk, with 1 Search-Head in either site (and indexers and heavy-...
by Splunker Communicator in Splunk Enterprise Security 02-11-2015
0 2
0
2
coolwater77
Can I customized the fields that I see for an incident ticket for the notable event in the incident review dashboard....
by coolwater77 Explorer in Splunk Enterprise Security 02-04-2015
4 9
4
9
FRoth
I installed the Splunk App for Enterprise Security, but all dashboards and reports are empty. The Splunk_TA_windows A...
by FRoth Contributor in Splunk Enterprise Security 02-02-2015
0 2
0
2
Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...