Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
coleman07
The sample data which comes with the TA-sav add-on has its timestamp in a weird hexadecimal format. It looks like th...
by coleman07 Path Finder in Splunk Enterprise Security 04-09-2015
0 3
0
3
mcronkrite
Can you put in the url field of the threat list a domain value? For example, these were where domains were listed xx...
by mcronkrite Splunk Employee Splunk Employee in Splunk Enterprise Security 03-27-2015
0 1
0
1
tkopchak
Any time I load the debug/refresh endpoint, correlation searches stop running. Or, at least, they stop producing nota...
by SplunkTrust SplunkTrust in Splunk Enterprise Security 03-26-2015
0 1
0
1
jonathan_cooper
I'm working on tuning our data model accelerations and the first problem I'm running into is that they never finish. ...
by jonathan_cooper Communicator in Splunk Enterprise Security 03-26-2015
7 8
7
8
adsplunk1
Good afternoon. This is related to Enterprise Security 3.1.1 build 219910. Is it possible to allow a non-admin user...
by adsplunk1 New Member in Splunk Enterprise Security 03-18-2015
0 2
0
2
RiccardoV
Hi, I am using Splunk 6.2.2 and Enterprise Security 3.1.1. I have a bunch of threat lists (the actual URLs are looku...
by RiccardoV Communicator in Splunk Enterprise Security 03-18-2015
1 1
1
1
coolwater77
Can I create a security operations workflows using the ES app? For example, if I want a ticket to be opened in the ti...
by coolwater77 Explorer in Splunk Enterprise Security 03-15-2015
1 5
1
5
Chubbybunny
I've disabled the Google search feature in ./SA-ThreatIntelligence/local/workflow_actions.conf and confirmed it is no...
by Chubbybunny Splunk Employee Splunk Employee in Splunk Enterprise Security 03-11-2015
1 1
1
1
dschmidt_cfi
I realize this will be simple for someone with more experience than I have. Running 2 search heads, 2 indexers, manag...
by dschmidt_cfi Path Finder in Splunk Enterprise Security 03-11-2015
2 13
2
13
mcronkrite
Can you have multiple domain names on single url field? Or does every row have to have single domain name?
by mcronkrite Splunk Employee Splunk Employee in Splunk Enterprise Security 03-07-2015
0 4
0
4
john_miller1
I have been testing the Splunk Add-on for Nessus and want to start using the feature with fresh data. Is there a way...
by john_miller1 Explorer in Splunk Enterprise Security 03-03-2015
0 1
0
1
skathpal
Hello Everyone, I need to setup the email output action for ES APP correlation Searches , I have found that we cant ...
by skathpal Explorer in Splunk Enterprise Security 02-26-2015
0 1
0
1
mzorzi
According to the documentation for ES Asset management here: http://docs.splunk.com/Documentation/ES/3.2.1/User/Asse...
by mzorzi Splunk Employee Splunk Employee in Splunk Enterprise Security 02-26-2015
1 1
1
1
BenjaminWyatt
We recently upgraded our Enterprise Security instance to v3.0 from v2.4. After the upgrade, I noticed that Correlatio...
by BenjaminWyatt Communicator in Splunk Enterprise Security 02-25-2015
0 4
0
4
mcronkrite
0
1
RiccardoV
Hi, I have a question about custom threatlists in Splunk App for Enterprise Security. If I add a new custom threatli...
by RiccardoV Communicator in Splunk Enterprise Security 02-18-2015
0 3
0
3
RiccardoV
Hi guys, I am wondering if I could use a binary file with my own format as threat list in Splunk ES app. That file co...
by RiccardoV Communicator in Splunk Enterprise Security 02-18-2015
0 1
0
1
Alteek
Hi, I"m running the Enterprise Security app and I"m facing the following issue: Notable events or Incidents are cre...
by Alteek Explorer in Splunk Enterprise Security 02-17-2015
0 2
0
2
chris
I'm trying to integrate McAfee data into ES and I am having difficulties using the datamodel command. Why does this ...
by chris Motivator in Splunk Enterprise Security 02-16-2015
1 2
1
2
Splunker
Hi all, Have a 2 site distributed-architecture of Splunk, with 1 Search-Head in either site (and indexers and heavy-...
by Splunker Communicator in Splunk Enterprise Security 02-11-2015
0 2
0
2
coolwater77
Can I customized the fields that I see for an incident ticket for the notable event in the incident review dashboard....
by coolwater77 Explorer in Splunk Enterprise Security 02-04-2015
4 9
4
9
FRoth
I installed the Splunk App for Enterprise Security, but all dashboards and reports are empty. The Splunk_TA_windows A...
by FRoth Contributor in Splunk Enterprise Security 02-02-2015
0 2
0
2
asonenthal
Splunkers, I am trying to get IIS log W3C log events into Enterprise Security App. I made the IIS events an eventtyp...
by asonenthal New Member in Splunk Enterprise Security 02-01-2015
0 3
0
3
hcheang
Hello, I was trying to understand the queries used for ES app and found that many searches are simplified as whateve...
by hcheang Path Finder in Splunk Enterprise Security 01-29-2015
1 4
1
4
Defiant81
I'm running 4 indexers, 1 search head and 1 master as my splunk enterprise architecture . I've read the instructions ...
by Defiant81 Explorer in Splunk Enterprise Security 01-27-2015
0 2
0
2
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...
Top Solution Authors