Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
hwang2021
Hello, I am new for Splunk ES.To configure the ES Incident Review, I use the default setting for the Time which shoul...
by hwang2021 Loves-to-Learn Lots in Splunk Enterprise Security 09-16-2022
0 2
0
2
amartin6
We are planning to upgrade ES from 6.6.2 to 7.0.1, one of the new features will have a pop up window indicating that ...
by amartin6 Path Finder in Splunk Enterprise Security 09-15-2022
0 0
0
0
drih
Hi, We use the threat intelligence app within Enterprise security and use the local IP intel csv (local_ip_intel.csv)...
by drih Engager in Splunk Enterprise Security 09-15-2022
1 0
1
0
yourfriend
Hello Splunk team, I have two doubts please help me with details, 1. We are using Splunk cloud platform for Enterpris...
by yourfriend Loves-to-Learn in Splunk Enterprise Security 09-13-2022
0 4
0
4
tonymorin
I want to zebra strip (gray, white, gray, white)/alternate the row colors in the triggered notable table in the Incid...
by tonymorin Explorer in Splunk Enterprise Security 09-13-2022
0 3
0
3
cdp_fap
I want to enable client authentication. so I midify $SPLUNK_HOME/etc/apps/splunk_httpinput/local/inputs.conf [http]di...
by cdp_fap Observer in Splunk Enterprise Security 09-13-2022
0 0
0
0
AntoineDRN
Hello Splunkers,   We had some trouble with notable events.  Long story short, by wanting edit one notable, something...
by AntoineDRN Path Finder in Splunk Enterprise Security 09-13-2022
0 0
0
0
aakwah
Hi, I'd like to change Notable Event row color or the color of any field in incident review dashboard to easily ident...
by aakwah Builder in Splunk Enterprise Security 09-13-2022
0 0
0
0
sivareddy
while opening into search head server get error as : View more information about your request (request ID = 631c96cc4...
by sivareddy Loves-to-Learn Lots in Splunk Enterprise Security 09-10-2022
0 0
0
0
Gabriel_CCI
Hi community! I have a dashboard that shows the alerts on table and in the graph, the questions is How I can link eac...
by Gabriel_CCI Explorer in Splunk Enterprise Security 09-06-2022
0 1
0
1
cjacklum
We are in SplunkCloud with ES 7.0.0 As a user with the sc_admin or ess_admin role when selecting an incident to edit,...
by cjacklum Engager in Splunk Enterprise Security 09-06-2022
0 1
0
1
MinaMina
Hello, I need to put sql server logs into Splunk for Enterprise Security. Is there any add-on available? I found an ...
by MinaMina New Member in Splunk Enterprise Security 09-06-2022
0 9
0
9
rockzers
i installed universal forwarder 4 machine this event log is getting my pci want to compare my event log and universal...
by rockzers Path Finder in Splunk Enterprise Security 09-01-2022
0 1
0
1
danielbb
Is there a comparison between ES and Chronicle Security of Google? A top official here wonders about it.
by danielbb Motivator in Splunk Enterprise Security 08-31-2022
0 1
0
1
apollo_sj
Hi All, We are running an Splunk action - run query (search) on a Phantom playbook which is active on every event com...
by apollo_sj New Member in Splunk Enterprise Security 08-26-2022
0 1
0
1
jack_lang
Hi, Imagine the role `A` has access to index=foobar, but roles 'B' and 'C' do not. Imagine Splunk Enterprise Security...
by jack_lang New Member in Splunk Enterprise Security 08-26-2022
0 1
0
1
sami2
I need to know where i can view the source index of the event that Splunk Enterprise Security take to make an alert, ...
by sami2 New Member in Splunk Enterprise Security 08-26-2022
0 2
0
2
davidem
Hi, I created a new Correlation Search that needs to generate notable, so in the "Adaptive Response Actions" I added ...
by davidem Explorer in Splunk Enterprise Security 08-26-2022
0 2
0
2
jmgonzalez
Hello, We are trying to modify the existing query in the "Remote Desktop Network Bruteforce" correlation search prese...
by jmgonzalez Observer in Splunk Enterprise Security 08-26-2022
0 3
0
3
marceldera
I am trying to remove duplicate from a field result: index=tenable* sourcetype="*" severity_description="*" | table s...
by marceldera Explorer in Splunk Enterprise Security 08-25-2022
0 1
0
1
Papoose1992
Hi All, What is the best way to integrate Samba AD logs for user activity with Splunk Cloud?  
by Papoose1992 Observer in Splunk Enterprise Security 08-23-2022
0 0
0
0
Gabriel_CCI
Hi. I need upgrade my Splunk Cluster, my current versión is 7.3.2  and I need upgrade to 8.0.10, but we have Enterpri...
by Gabriel_CCI Explorer in Splunk Enterprise Security 08-16-2022
0 1
0
1
Ananta
Hi All, We are planning to upgrade Splunk ES from 6.2 to 7.0.1. In Release Notes of 7.0.1 deprecated features, its me...
by Ananta New Member in Splunk Enterprise Security 08-15-2022
0 0
0
0
sr_dhinesh
Hello team: i am working on Splunk Endpoint Data Model and i have windows audit logs in splunk. My concern is if i we...
by sr_dhinesh Path Finder in Splunk Enterprise Security 08-11-2022
0 8
0
8
cybersej
Hi Splunkers, I will planning entegration splunk on our aws envirement but I m beginner on aws so please could you he...
by cybersej Observer in Splunk Enterprise Security 08-10-2022
0 2
0
2
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...