Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
schandrasekar
We have upgraded Splunk Enterprise recently to 8.0.2.1 and all the apps in our environment to the latest version. One...
by schandrasekar Loves-to-Learn in Splunk Enterprise Security 07-01-2022
0 8
0
8
dtccsundar
Hi ,I have  4 fields and those need to be in a tabular format .Out of which one field has the ratings which need to b...
by dtccsundar Path Finder in Splunk Enterprise Security 07-01-2022
0 4
0
4
Valen1
What parameter can i modify in limits.conf to solve that? The percentage of non high priority searches delayed (80%) ...
by Valen1 Engager in Splunk Enterprise Security 07-01-2022
1 3
1
3
kkrises
Hello Splunkers, I configured a new Notable suppression in ES for a repeated notable based on source IP. I could see ...
by kkrises Path Finder in Splunk Enterprise Security 07-01-2022
0 4
0
4
Abhi89
I am trying to find out what purpose drop_dm_object_name() serves.
by Abhi89 New Member in Splunk Enterprise Security 06-30-2022
0 4
0
4
JD_Sample
Is there a way to customize which additional fields to show for which Notable event /Co-relation search without affec...
by JD_Sample Engager in Splunk Enterprise Security 06-29-2022
1 3
1
3
Treize
Hi, I am a beginner.I have a correlation rule that :- searches for IP addresses that are port scans- search in the lo...
by Treize Path Finder in Splunk Enterprise Security 06-28-2022
0 3
0
3
sssinqiry5
Hi all,My team needs to clear an alert with a totally different department before we consider it "published" for the ...
by sssinqiry5 Engager in Splunk Enterprise Security 06-23-2022
0 1
0
1
ksahu
I have a SHC consisting of 4 SHs (Splunk on-prem on AWS). One or the other SHs seem to go into down state. The only i...
by ksahu New Member in Splunk Enterprise Security 06-21-2022
0 1
0
1
Lowell
Splunk Enterprise Security is deployed to a Search Head Cluster, along with a bunch of applicable TAs. Deployments ar...
by Lowell Super Champion in Splunk Enterprise Security 06-20-2022
5 13
5
13
bhargavg
Hi All, We are facing a weird issue where we are unable to see any new incidents on PCI compliance >Incidents review....
by bhargavg New Member in Splunk Enterprise Security 06-18-2022
0 0
0
0
muhammadalavi19
Hi We are using Splunk ES 7.0 in our SOC environment. After upgrading to ES 7.0 we are getting the following issue du...
by muhammadalavi19 Loves-to-Learn in Splunk Enterprise Security 06-18-2022
0 0
0
0
Agent31
I'm using searches which are relatively noisy and difficult to simply write exclusions for, so one way that I've been...
by Agent31 Engager in Splunk Enterprise Security 06-16-2022
0 0
0
0
dmuley
I have the event that looks like below    2022-06-15 19:59:57.489 threadId=L4GFP2275S1K class="ActiveSession" mname="...
by dmuley Explorer in Splunk Enterprise Security 06-15-2022
0 4
0
4
residualfail
Hello, I found a ton of eventtypes for the vmware agent module like AGENT_CONNECTED, AGENT_RECONNECTED, AGENT_SHUTDOW...
by residualfail New Member in Splunk Enterprise Security 06-14-2022
0 0
0
0
deodeshm
As I understand es_notable_events is KVStore and it stores notable event information for last 48 hours/ also there is...
by deodeshm Explorer in Splunk Enterprise Security 06-09-2022
0 1
0
1
sheamus69
The AccountExpires field in an AD log is described as: The date when the account expires. This value represents the...
by sheamus69 Communicator in Splunk Enterprise Security 06-07-2022
0 2
0
2
spectrum2035
Hello, We would like to use the latest CIM version (4.13.0) in order to use the Endpoint datamodel which is not avail...
by spectrum2035 Explorer in Splunk Enterprise Security 05-31-2022
0 3
0
3
oylkm
I have a threat activity rule that looks at both internal IPs attempting communication externally to malicious IPs ba...
by oylkm Explorer in Splunk Enterprise Security 05-30-2022
0 2
0
2
SamHTexas
The error says "Threat list download from https://raw.githubusercontent.com/mitre/cti/master/enterprise-attack/enterp...
by SamHTexas Builder in Splunk Enterprise Security 05-25-2022
0 3
0
3
ncsasecops
We are seeing this vulnerability show up via qualys vuln scanning on both our dev and production splunk instances. I ...
by ncsasecops Engager in Splunk Enterprise Security 05-25-2022
2 2
2
2
Abdullah
Hi,   Closing high number of incident was always done but the slowness is a new thing.   Now we are facing the slowne...
by Abdullah Explorer in Splunk Enterprise Security 05-25-2022
0 1
0
1
fedejko
Hi, I have the following case which I can't get around. My search returns something like this: In order to help secu...
by fedejko Explorer in Splunk Enterprise Security 05-24-2022
0 5
0
5
zargaran
Hi geeks,I integrated the TheHive and Cortex with Splunk ES for getting some alerts after triggering the correlation ...
by zargaran Observer in Splunk Enterprise Security 05-23-2022
0 0
0
0
jimish
Unable to pull similar number 53726516638.77 (in billion) using chart for past 7 days. Dashboard only pulls data for ...
by jimish Explorer in Splunk Enterprise Security 05-20-2022
0 4
0
4
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...