Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
echojacques
In Enterprise Security I have this correlation search which I believe includes searching through the previous 24 hour...
by echojacques Builder in Splunk Enterprise Security 08-27-2013
0 5
0
5
coolwater77
Is it possible to add/attach new events that are generated using correlation searches or manually searches to an exi...
by coolwater77 Explorer in Splunk Enterprise Security 08-26-2013
0 1
0
1
coolwater77
I am trying to understand if I can track changes related to the incidents managed by the ES App.Below are my requirem...
by coolwater77 Explorer in Splunk Enterprise Security 08-26-2013
0 3
0
3
echojacques
My Splunk + Enterprise Security installation came with 51 canned correlation searches. For example, searches to disc...
by echojacques Builder in Splunk Enterprise Security 08-23-2013
1 4
1
4
coolwater77
As I understand the splunk app for Enterprise Security creates a number of TSIDX namespaces that are used to store su...
by coolwater77 Explorer in Splunk Enterprise Security 08-23-2013
0 3
0
3
echojacques
Hi everyone, I have the OPSECLEA TA installed and I'd like to strip out certain events (all destination port 80 (HTT...
by echojacques Builder in Splunk Enterprise Security 08-18-2013
0 1
0
1
jaoui
The messages at the top of the screen populates with the following error: lookup_expander: Some extra fields were pre...
by jaoui Path Finder in Splunk Enterprise Security 08-12-2013
0 1
0
1
MattQ
What deployments of Splunk support the enterprise security app? I want to try a demo on my older version (less pro...
by MattQ Explorer in Splunk Enterprise Security 07-12-2013
0 1
0
1
glancaster
I enabled SA-Eventgen for my ES App and now I have many faux security events. This seems to be a demo to fill the das...
by glancaster Path Finder in Splunk Enterprise Security 07-08-2013
0 5
0
5
SplunkFu
Hi there, I was just looking through our splunkd logs, and I notice multiple errors for the following: <dateTime> ...
by SplunkFu Path Finder in Splunk Enterprise Security 06-25-2013
1 4
1
4
it7272
I am looking to download the 2.2.0 ES application, where can I find it?
by it7272 Engager in Splunk Enterprise Security 05-28-2013
0 4
0
4
wweiland
I have the Enterprise Security Suite App installed and working. I can run a geoip search in the Search App and that ...
by wweiland Contributor in Splunk Enterprise Security 05-22-2013
0 1
0
1
ravitalele
Hi, How do I try this application? Thanks, Ravi
by ravitalele New Member in Splunk Enterprise Security 04-17-2013
0 1
0
1
sdwilkerson
Folks, I'm at a site with 3 search heads and 6 indexers. One of the SH is ES-2.0.2. All SH and Indexers were upgra...
by sdwilkerson Contributor in Splunk Enterprise Security 02-08-2013
1 2
1
2
jcoquico
We have recently installed ES for Splunk and have over 150K+ incidents that I want to close that were opened prior to...
by jcoquico Engager in Splunk Enterprise Security 02-01-2013
1 1
1
1
jsmithos2
How can I download a copy for the Enterprise Security App and try it out?
by jsmithos2 New Member in Splunk Enterprise Security 11-28-2012
0 1
0
1
rroberts
SA-ThreatIntelligence/bin/getiblocklist.py app=SA-ThreatIntelligence url=http://list3.iblocklist.com/files/bt_spywa...
by rroberts Splunk Employee Splunk Employee in Splunk Enterprise Security 10-24-2012
0 1
0
1
perlish
Hi, who can tell me how can i try this app? http://splunk-base.splunk.com/apps/22297/splunk-app-for-enterprise-securi...
by perlish Communicator in Splunk Enterprise Security 10-09-2012
0 3
0
3
hulahoop
Splunk has many capabilities for correlating events over time, by keyword, by dynamic transactions, and more. It als...
by hulahoop Splunk Employee Splunk Employee in Splunk Enterprise Security 10-04-2012
2 5
2
5
sf_user_199
We are using Splunk to implement file integrity monitoring, but our security team has a requirement that I'm having t...
by sf_user_199 Path Finder in Splunk Enterprise Security 08-30-2012
0 2
0
2
rroberts
The Enterprise Security Install App says I have the latest version of ES 2.0.1 . Why is it not prompting to upgrade t...
by rroberts Splunk Employee Splunk Employee in Splunk Enterprise Security 07-03-2012
0 2
0
2
Splunker
Folks, In the following Splunk installation [SH -> IDX -> Heavy-Forwarder -> Multiple UFs + Syslog] Using Enterpris...
by Splunker Communicator in Splunk Enterprise Security 07-02-2012
0 2
0
2
rroberts
While working in the ESS app searching for tag=attack last 60 mins time range I get about 1,262 events. I get two war...
by rroberts Splunk Employee Splunk Employee in Splunk Enterprise Security 06-29-2012
1 3
1
3
brianmarc
I see some apps that state they need to be deployed to indexers. However I see no usage of the “TRANSFORMS-” in the ...
by brianmarc New Member in Splunk Enterprise Security 05-15-2012
0 1
0
1
cristone
We have a Partner Enterprise License and we want to test the following app: http://splunk-base.splunk.com/apps/22297/...
by cristone New Member in Splunk Enterprise Security 04-03-2012
0 1
0
1
Get Updates on the Splunk Community!

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Data Drivers: How We're Streaming Real-Time F1 Telemetry Directly into Splunk ...

Data Drivers: Every Lap Tells a Story The Spectacle Two F1 racing sims go head-to-head on the .conf26 show ...