Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
smith_
Hi,I aimed to merge the "dropped" and "blocked" values under the "IDS_Attacks.action" field in the output of the data...
by smith_ Builder in Splunk Enterprise Security 10-25-2023
0 4
0
4
smith_
Hi,I'm trying to reduce the noise out of these EventCodes which we can exclude in the enterprise security point of vi...
by smith_ Builder in Splunk Enterprise Security 10-25-2023
0 5
0
5
neerajs_81
Hi, I need to report on when a Notable alert was changed from the default "unassigned" status to " Acknowledged" stat...
by neerajs_81 Builder in Splunk Enterprise Security 10-25-2023
0 1
0
1
alaalsanea
DearsHow to find out what Devices (Switch, Router, etc.), operating systems (Windows, linux, MacOs, etc.), applicatio...
by alaalsanea Observer in Splunk Enterprise Security 10-23-2023
0 1
0
1
StefanoA
Hello everyone,I am concerned about single-event-match (e.g. observable-based) searches and the eventual indexing del...
by StefanoA Explorer in Splunk Enterprise Security 10-19-2023
0 1
0
1
Albert_Cyber
We are in the process of deploying our endpoint logging strategy. Right now, we are using CrowdStrike as our EDR. As ...
by Albert_Cyber Explorer in Splunk Enterprise Security 10-19-2023
0 1
0
1
Albert_Cyber
I am pretty new to ES correlation seraches and I am trying to figure out how to add additionals fields to notable eve...
by Albert_Cyber Explorer in Splunk Enterprise Security 10-17-2023
0 3
0
3
pc1234
A user is unable to access investigations in Enterprise Security (version ES 7.1.1) on Splunk Cloud (Splunk 9.0.2) . ...
by pc1234 Explorer in Splunk Enterprise Security 10-17-2023
2 0
2
0
yafei
想了解下,SPlunk 单台服务器,最多可以接入多大的数据量 ,可以给工
by yafei New Member in Splunk Enterprise Security 10-16-2023
0 3
0
3
mjuestel2
Hello:I recently started playing with the Risk framework, RBA etc. Most of my Risk Analysis dashboard is working with...
by mjuestel2 Path Finder in Splunk Enterprise Security 10-12-2023
0 1
0
1
cjharmening
Hello all,  We are wanting to enrich events as they become notables in ES before they are sent onto Mission control. ...
by cjharmening Loves-to-Learn Lots in Splunk Enterprise Security 10-11-2023
0 1
0
1
DatDuongVNCSG
Hi community Splunk, I have a issus when install Splunk Enterprise Security in Deployer. I have Splunk enviroment, it...
by DatDuongVNCSG New Member in Splunk Enterprise Security 10-11-2023
0 0
0
0
smith_
HiI'm seeing an error message in my es search head, How we can sort out this issue Search peer idx-xxx.com has the fo...
by smith_ Builder in Splunk Enterprise Security 10-09-2023
0 3
0
3
Rob2520
Hi Splunkers, We have a ton of bookmarked content in Splunk Security Essentials App on one of our Dev Splunk search h...
by Rob2520 Communicator in Splunk Enterprise Security 10-07-2023
0 2
0
2
Albert_Cyber
Hello everyone,I am trying to enable some basic detections that found from the Splunk Security Essentials app. We do ...
by Albert_Cyber Explorer in Splunk Enterprise Security 10-06-2023
0 2
0
2
almomani
I have an old stand alone search head with Enterprise security and I'm migrating to a new search head cluster.Now I h...
by almomani New Member in Splunk Enterprise Security 10-03-2023
0 2
0
2
VK18
We have activated several data models for use with Splunk Enterprise security scenarios and are interested in clarify...
by VK18 Explorer in Splunk Enterprise Security 10-03-2023
0 2
0
2
drew19
Hi,we are using Splunk ES with notable events and suppressions. For sake of completeness, we have alerts that produce...
by drew19 Path Finder in Splunk Enterprise Security 10-03-2023
0 2
0
2
grotti
I would like a search query that would display a graph with the number of closed notables divided by urgency in the l...
by grotti Engager in Splunk Enterprise Security 10-03-2023
0 2
0
2
nelaturivijay
Hi All,Is there a way to retrieve a specific alert without using short ID in the incident review page?I was thinking ...
by nelaturivijay Observer in Splunk Enterprise Security 10-01-2023
0 0
0
0
BernardEAI
I have loaded a SSL Certificate on our development server (Splunk 8.1.4). I added the following to the server.conf fi...
by BernardEAI Communicator in Splunk Enterprise Security 09-28-2023
0 2
0
2
packetrider
When you create notes in Splunk ES you can format the notes with tabs and carriage returns.  When the note saves and ...
by packetrider Engager in Splunk Enterprise Security 09-28-2023
1 1
1
1
gauravu_14
I have created a tag for a key-value pair (dvc=IP_Address) and shared it will all the apps. Which doing a search for ...
by gauravu_14 Explorer in Splunk Enterprise Security 09-28-2023
0 2
0
2
daniel333
All, I am setting up asset center in Splunk ES/PCI. The idea of an Asset priority is sorta vague. Is it left that w...
by daniel333 Builder in Splunk Enterprise Security 09-26-2023
1 7
1
7
calvinmcelroy
Hello,   Our security team has had a need of a asset management tool to keep track of our hardware and software inven...
by calvinmcelroy Path Finder in Splunk Enterprise Security 09-26-2023
0 2
0
2
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...