Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
calvinmcelroy
Hello,   Our security team has had a need of a asset management tool to keep track of our hardware and software inven...
by calvinmcelroy Path Finder in Splunk Enterprise Security 09-26-2023
0 2
0
2
phamanh1652
In System Center dashboard, only *NIX system data is available, not Windows system. I've already install Splunk Add-o...
by phamanh1652 Path Finder in Splunk Enterprise Security 09-13-2023
0 0
0
0
kellybee
Hi i am kinda new to Splunk and I'm having this trouble `A script exited abnormally with exit status: 1" input=".$SPL...
by kellybee Loves-to-Learn Lots in Splunk Enterprise Security 09-11-2023
0 2
0
2
linaaabad
Are there pre-configured or default Dashboards associated with this Add-on?  Is the Add-on suppose to show up under A...
by linaaabad Observer in Splunk Enterprise Security 09-10-2023
0 3
0
3
joe_kraxner
When you expand the details of a Notable Event in Enterprise Security (ES) 3.x there is a heading called “Contributin...
by joe_kraxner Explorer in Splunk Enterprise Security 09-07-2023
5 2
5
2
lucky
HI team,   I need to extract the new fields by using rex for below raw data  1.ResponseCode 2.url message: INFO [nio-...
by lucky Explorer in Splunk Enterprise Security 09-03-2023
0 1
0
1
TJT
Is there a way to view license usage from the Splunk search head? I'm on Splunk 9.0.3.I've attempted to forward licen...
by TJT Loves-to-Learn Lots in Splunk Enterprise Security 09-03-2023
0 1
0
1
lucky
 HI ,please help to get new field URI by using rex /area/label/health/readiness||||||||||METRICS|--
by lucky Explorer in Splunk Enterprise Security 09-01-2023
0 2
0
2
edwardrose
Hello All, I am testing the upgrade from ES 6.2.0 to 6.6.2.  When I do the upgrade it fails with OSError type 28 no s...
by edwardrose Contributor in Splunk Enterprise Security 08-28-2023
0 3
0
3
b_chris21
Hello, I have a Splunk ES instance on AWS. All logs are forwarded there from a Splunk HF (full forwarding - no indexi...
by b_chris21 Communicator in Splunk Enterprise Security 08-24-2023
0 4
0
4
canalesjac
I would like retrieve data from Epic Hyperspace Logs via Syslog. I know you can use the Epic APIs like FIHR but I wou...
by canalesjac Path Finder in Splunk Enterprise Security 08-24-2023
0 3
0
3
f_f
Hello guys is it possible to start to monitor metrics for the host where we are collecting logs in Splunk ES? Thank y...
by f_f New Member in Splunk Enterprise Security 08-22-2023
0 2
0
2
lb888558
Can anyone please help on the WORKSPACE ONE integration with SPLUNK? Scenario : We have SaaS setup for WS-1 (connecto...
by lb888558 Engager in Splunk Enterprise Security 08-17-2023
1 2
1
2
EssKay
Hi, I got confused when running the following search to identify what are the enabled searches in the environment : |...
by EssKay Engager in Splunk Enterprise Security 08-17-2023
0 1
0
1
smith_
Hi,I would like to learn how to save an SPL search and be able to retrieve it whenever necessary. I'm unsure about th...
by smith_ Builder in Splunk Enterprise Security 08-16-2023
0 1
0
1
Mohammed123
some issues with short id we cant able to search through incident review, actually the paloalto saor is integrated wi...
by Mohammed123 Loves-to-Learn Everything in Splunk Enterprise Security 08-14-2023
0 1
0
1
qq-stan
Splunk ES documentation https://docs.splunk.com/Documentation/ES/7.1.1/Admin/Downloadthreatfeed#Add_a_URL-based_threa...
by qq-stan Explorer in Splunk Enterprise Security 08-07-2023
0 2
0
2
Nawab
I want to create a use case below is the scenario Let's suppose we have a device that will create a new temp user for...
by Nawab Communicator in Splunk Enterprise Security 08-07-2023
0 5
0
5
VK18
Hi All, There are few risk notable events getting generated in the Incident review page as part of correlation search...
by VK18 Explorer in Splunk Enterprise Security 08-06-2023
0 6
0
6
elliotp
It is possible to clone dashboards from the Enterprise Security app into a private custom app so that I can make modi...
by elliotp Observer in Splunk Enterprise Security 08-02-2023
0 0
0
0
sigma
we have some services, each produces some logs. these logs aggregated and store in a minio bucket (not aws! just a on...
by sigma Path Finder in Splunk Enterprise Security 07-31-2023
0 0
0
0
gwes77
Hello all, I need help manually mapping a log source that has no supported add on. I entered in two event types wit...
by gwes77 Explorer in Splunk Enterprise Security 07-31-2023
0 2
0
2
JLopez
Hi Splunkers,I need to show to some stakeholders the correlation searches that we have enabled and are aligned to the...
by JLopez Explorer in Splunk Enterprise Security 07-31-2023
0 1
0
1
WillBryant
I'm trying to run a Python script as part of an Adaptive Response Action.  In Splunk ES, I go to Enterprise Security ...
by WillBryant New Member in Splunk Enterprise Security 07-31-2023
0 1
0
1
NotWilko
Hello all! I am attempting to dynamically add 'Next Steps' to a notable event based off a lookup table in my Correlat...
by NotWilko Engager in Splunk Enterprise Security 07-27-2023
1 0
1
0
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...