Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
deodeshm
As I understand es_notable_events is KVStore and it stores notable event information for last 48 hours/ also there is...
by deodeshm Explorer in Splunk Enterprise Security 06-09-2022
0 1
0
1
sheamus69
The AccountExpires field in an AD log is described as: The date when the account expires. This value represents the...
by sheamus69 Communicator in Splunk Enterprise Security 06-07-2022
0 2
0
2
spectrum2035
Hello, We would like to use the latest CIM version (4.13.0) in order to use the Endpoint datamodel which is not avail...
by spectrum2035 Explorer in Splunk Enterprise Security 05-31-2022
0 3
0
3
oylkm
I have a threat activity rule that looks at both internal IPs attempting communication externally to malicious IPs ba...
by oylkm Explorer in Splunk Enterprise Security 05-30-2022
0 2
0
2
SamHTexas
The error says "Threat list download from https://raw.githubusercontent.com/mitre/cti/master/enterprise-attack/enterp...
by SamHTexas Builder in Splunk Enterprise Security 05-25-2022
0 3
0
3
ncsasecops
We are seeing this vulnerability show up via qualys vuln scanning on both our dev and production splunk instances. I ...
by ncsasecops Engager in Splunk Enterprise Security 05-25-2022
2 2
2
2
Abdullah
Hi,   Closing high number of incident was always done but the slowness is a new thing.   Now we are facing the slowne...
by Abdullah Explorer in Splunk Enterprise Security 05-25-2022
0 1
0
1
fedejko
Hi, I have the following case which I can't get around. My search returns something like this: In order to help secu...
by fedejko Explorer in Splunk Enterprise Security 05-24-2022
0 5
0
5
zargaran
Hi geeks,I integrated the TheHive and Cortex with Splunk ES for getting some alerts after triggering the correlation ...
by zargaran Observer in Splunk Enterprise Security 05-23-2022
0 0
0
0
jimish
Unable to pull similar number 53726516638.77 (in billion) using chart for past 7 days. Dashboard only pulls data for ...
by jimish Explorer in Splunk Enterprise Security 05-20-2022
0 4
0
4
JakeInfoSec
I'm currently trying to upload a malware feed into Threat Intelligence Management.The feed itself is being pulled fro...
by JakeInfoSec Explorer in Splunk Enterprise Security 05-20-2022
1 2
1
2
Zacknoid
Hello everyone, I am trying to separate data getting into the main index from particular hosts. I am trying  Transfor...
by Zacknoid Explorer in Splunk Enterprise Security 05-20-2022
0 3
0
3
halleyglen
Facing issues with KVStore on Enterprise Security. Dashboards show an error "Unable to load results". Is there any co...
by halleyglen Explorer in Splunk Enterprise Security 05-19-2022
3 8
3
8
jravida
Hi folks, I seem to have the remnants of a role, being called up, and failing to exist. The role is related to the E...
by jravida Communicator in Splunk Enterprise Security 05-18-2022
1 3
1
3
Splunk2210
While editing the Notable, we have options called "Edit selected".  Can anyone help me with how to put the limit(numb...
by Splunk2210 Observer in Splunk Enterprise Security 05-17-2022
0 0
0
0
PickleRick
I'm wondering about possibilities to set up a separate ES's for different teams. Due to some mergers and acquisitions...
by SplunkTrust SplunkTrust in Splunk Enterprise Security 05-16-2022
0 2
0
2
sswansonchtr
Under the 'Incident Review' dashboard, I want to add a Status type of 'False Positive' so I can easily find these and...
by sswansonchtr Path Finder in Splunk Enterprise Security 05-12-2022
0 4
0
4
Woodpecker
Hi,I have a CS, which runs every 6mins looking back -65m and -5m.. It triggered a notable alert, where for the same d...
by Woodpecker Path Finder in Splunk Enterprise Security 05-12-2022
0 0
0
0
arangineni
We have a setup where the AWS KMS logs are sent to Splunk HEC through below flow. We are getting JSON event format bu...
by arangineni Explorer in Splunk Enterprise Security 05-11-2022
0 0
0
0
Gene
Dear Splunkers, can you please advise or direct my to right place on following question:we need to send notification ...
by Gene Path Finder in Splunk Enterprise Security 05-11-2022
0 2
0
2
praju
Hi Team, Could you please help me on this request. I have a correlation search working fine and need to exclude these...
by praju New Member in Splunk Enterprise Security 05-10-2022
0 1
0
1
waja1n0z1
Hi All,I am investigating the possibility of consolidating our separate standalone ES Searchheads into a single clust...
by waja1n0z1 Loves-to-Learn in Splunk Enterprise Security 05-04-2022
0 0
0
0
mjones414
Greetings.I've been trying to build a correlation search that sets a default disposition value when it runs but so fa...
by mjones414 Contributor in Splunk Enterprise Security 05-03-2022
0 0
0
0
sitthiporns
Has anyone found this error event?  
by sitthiporns Explorer in Splunk Enterprise Security 05-03-2022
0 0
0
0
cyber_Maddy
query to find out activity towards a particular URL eg: URL - https://www.microsoft.com/en-us/security
by cyber_Maddy Engager in Splunk Enterprise Security 05-02-2022
0 2
0
2
Get Updates on the Splunk Community!

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...