Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
hkarthikeyan
0
3
neerajs_81
Hello,  In ES when we run the following macro for Last 30 mins or Last 24 H time range,  splunk ends up displaying re...
by neerajs_81 Builder in Splunk Enterprise Security 07-29-2022
0 6
0
6
yourfriend
Hi All,Our Client has sell off some part of it to another company, Here I am using "CL"  as our client "ZX" as new co...
by yourfriend Loves-to-Learn in Splunk Enterprise Security 07-28-2022
0 0
0
0
dm1
I just upgraded Splunk ES from 6.2.0 to 7.0.1 on Splunk Core version 8.1.5. However, some of the dashboards like Clou...
by dm1 Contributor in Splunk Enterprise Security 07-25-2022
0 0
0
0
aranjan
Need help in building Rest API in splunk ES for Oracle IDCS
by aranjan New Member in Splunk Enterprise Security 07-22-2022
0 0
0
0
jkay2016
Hi I noticed a quite a number job running in the background attributed to the macro "modular_action_invocations". Fro...
by jkay2016 Engager in Splunk Enterprise Security 07-22-2022
2 3
2
3
yourfriend
Hello Team,                          We are using Enterprise security in our environment and we have created correlat...
by yourfriend Loves-to-Learn in Splunk Enterprise Security 07-21-2022
0 0
0
0
swagner1965
Hi, We use a few stand alone systems for scanning media and other tasks in our group. We are required to retrieve a...
by swagner1965 Path Finder in Splunk Enterprise Security 07-21-2022
0 3
0
3
warsaw
I have a correlation search where 'dest' field is present, and in drilldown search I have mentioned      | search des...
by warsaw Loves-to-Learn Lots in Splunk Enterprise Security 07-20-2022
0 7
0
7
Azeemering
An Example:We have defined two malicious urls in the local_http_intel This triggers false positives in the Threat Ac...
by Azeemering Builder in Splunk Enterprise Security 07-19-2022
0 0
0
0
mdicenzo
I am trying to include dynamic names for a notable event that I have triggering. When I try to use $variable$ it just...
by mdicenzo Explorer in Splunk Enterprise Security 07-11-2022
0 0
0
0
yourfriend
Hi Team,                    We are reviewing the use cases in our Splunk Enterprise security, We have given Throttlin...
by yourfriend Loves-to-Learn in Splunk Enterprise Security 07-08-2022
0 7
0
7
SIEMStudent
Hi Splunkers,I have an issue with the use of Data Model, eval command and sourcetype as filter. Let me explain better...
by SIEMStudent Path Finder in Splunk Enterprise Security 07-05-2022
0 1
0
1
schandrasekar
We have upgraded Splunk Enterprise recently to 8.0.2.1 and all the apps in our environment to the latest version. One...
by schandrasekar Loves-to-Learn in Splunk Enterprise Security 07-01-2022
0 8
0
8
dtccsundar
Hi ,I have  4 fields and those need to be in a tabular format .Out of which one field has the ratings which need to b...
by dtccsundar Path Finder in Splunk Enterprise Security 07-01-2022
0 4
0
4
Valen1
What parameter can i modify in limits.conf to solve that? The percentage of non high priority searches delayed (80%) ...
by Valen1 Engager in Splunk Enterprise Security 07-01-2022
1 3
1
3
kkrises
Hello Splunkers, I configured a new Notable suppression in ES for a repeated notable based on source IP. I could see ...
by kkrises Path Finder in Splunk Enterprise Security 07-01-2022
0 4
0
4
Abhi89
I am trying to find out what purpose drop_dm_object_name() serves.
by Abhi89 New Member in Splunk Enterprise Security 06-30-2022
0 4
0
4
JD_Sample
Is there a way to customize which additional fields to show for which Notable event /Co-relation search without affec...
by JD_Sample Engager in Splunk Enterprise Security 06-29-2022
1 3
1
3
Treize
Hi, I am a beginner.I have a correlation rule that :- searches for IP addresses that are port scans- search in the lo...
by Treize Path Finder in Splunk Enterprise Security 06-28-2022
0 3
0
3
sssinqiry5
Hi all,My team needs to clear an alert with a totally different department before we consider it "published" for the ...
by sssinqiry5 Engager in Splunk Enterprise Security 06-23-2022
0 1
0
1
ksahu
I have a SHC consisting of 4 SHs (Splunk on-prem on AWS). One or the other SHs seem to go into down state. The only i...
by ksahu New Member in Splunk Enterprise Security 06-21-2022
0 1
0
1
Lowell
Splunk Enterprise Security is deployed to a Search Head Cluster, along with a bunch of applicable TAs. Deployments ar...
by Lowell Super Champion in Splunk Enterprise Security 06-20-2022
5 13
5
13
bhargavg
Hi All, We are facing a weird issue where we are unable to see any new incidents on PCI compliance >Incidents review....
by bhargavg New Member in Splunk Enterprise Security 06-18-2022
0 0
0
0
muhammadalavi19
Hi We are using Splunk ES 7.0 in our SOC environment. After upgrading to ES 7.0 we are getting the following issue du...
by muhammadalavi19 Loves-to-Learn in Splunk Enterprise Security 06-18-2022
0 0
0
0
Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...