Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
tsa
We are observing delayed ingestion of logs from neuvector application, via syslog method 
by tsa New Member in Splunk Enterprise Security 09-28-2025
0 2
0
2
EMDEEEEE
Can someone provide queries for the below Password reset events for a userinteractive and non interactive login attem...
by EMDEEEEE New Member in Splunk Enterprise Security 09-28-2025
0 4
0
4
splunkreal
Hello guys, since 08/20/2025 we have issues in ES downloading these feeds from Splunk servers. When we try with curl ...
by splunkreal Motivator in Splunk Enterprise Security 09-22-2025
0 2
0
2
aminab2421
Helloi have splunk enterprise 10.0.0 and install splunk enterprise security  8.1.1 when config cim on splunk es , sho...
by aminab2421 Observer in Splunk Enterprise Security 09-21-2025
0 2
0
2
Francois_Luno
I'm ingesting Fortigate logs using the Splunk_TA_fortinet_fortigate add-on, and I've noticed that these logs are not ...
by Francois_Luno Loves-to-Learn in Splunk Enterprise Security 09-17-2025
0 3
0
3
waddellt
Getting error:Upload failed: Package is too large, must be less than 512 MB 
by waddellt Engager in Splunk Enterprise Security 09-16-2025
0 1
0
1
muhammadfahimma
After a recent upgrade to Splunk ES 8.0.2, we have observed that none of the drill downs for detection based searches...
by muhammadfahimma Explorer in Splunk Enterprise Security 09-15-2025
0 7
0
7
Inayath_khan
Unable to initialize modular input "whois" defined in the app "SA-NetworkProtection": Introspecting scheme=whois: scr...
by Inayath_khan Path Finder in Splunk Enterprise Security 09-14-2025
0 1
0
1
azer271
The Analytics Story Onboarding Assistant keeps on displaying "0% uploaded" everytime I press enable the rules (using ...
by azer271 Path Finder in Splunk Enterprise Security 09-09-2025
0 2
0
2
ehsansplunk
I am a Splunk Partner with license admin access.I’ve already downloaded the NFR license for Splunk Enterprise, but I ...
by ehsansplunk New Member in Splunk Enterprise Security 08-31-2025
0 5
0
5
D77
In Splunk v7 we used to search index=_internal to find events that contained GET AND "/results/export?output" This pr...
by D77 Loves-to-Learn Lots in Splunk Enterprise Security 08-30-2025
0 6
0
6
MsF-2000
Hi All I am trying to add new lines in mail body of the already scheduled export as PNG, when clicked on the dashboar...
by MsF-2000 Path Finder in Splunk Enterprise Security 08-30-2025
0 0
0
0
fraserphillips
Sorry if this is a simple question, or one that may have been solved before.  I haven't located anything to help yet....
by fraserphillips Engager in Splunk Enterprise Security 08-25-2025
0 5
0
5
Joei
After pulling cases from ES to Phantom a certain label is assigned to the event , later it is automatically promoted ...
by Joei Engager in Splunk Enterprise Security 08-24-2025
0 1
0
1
akai
Hello,I have create a custom role and assigned the same permissions as ess_user, including adding it to the enforce_e...
by akai Explorer in Splunk Enterprise Security 08-22-2025
0 5
0
5
alatif113
Is there a way to automatically escalate a finding (or set of findings) to an investigation in Splunk Enterprise Secu...
by alatif113 New Member in Splunk Enterprise Security 08-20-2025
0 1
0
1
bishtk
Dear all,Facing an issue wherein few notables urgency getting changed post getting autoclose. i refer to splunk docs ...
by bishtk Communicator in Splunk Enterprise Security 08-14-2025
0 2
0
2
richardphung
Greetings-- I installed SA-Investigator on our ESSearchHead, but I do not understand how to launch the App. It appea...
by richardphung Communicator in Splunk Enterprise Security 08-08-2025
1 3
1
3
pdgill314
So, I have been struggling with this for a few days. I have thrown it against generative AI and not getting exactly w...
by pdgill314 Path Finder in Splunk Enterprise Security 08-05-2025
0 2
0
2
Dolly
Why do we find postgres in /apps/splunk/splunkforwarder/quarantined_files/bin/postgres even if we have upgraded to 9....
by Dolly Engager in Splunk Enterprise Security 08-04-2025
0 4
0
4
DeanDeleon0
We're trying to customize the Meantime to Triage and Meantime to Resolution queries in the ES Executivity Summary das...
by DeanDeleon0 Path Finder in Splunk Enterprise Security 08-01-2025
0 0
0
0
Giancarlo_Pasq
Hi,I need to create an investigation with SOAR.When I create the investigation, it doesn't link the Finding to the In...
by Giancarlo_Pasq New Member in Splunk Enterprise Security 08-01-2025
0 0
0
0
hl
Hello,    I see there are lots of Cisco event based detections and not many palo alto or checkpoint (fw, ids/ips, thr...
by hl Path Finder in Splunk Enterprise Security 07-29-2025
0 2
0
2
ejahnke
Hello fellow ES 8.X enjoyer.We have a few Splunk Cloud customer that got upgrade to ES 8.1. We have noticed that all ...
by ejahnke Explorer in Splunk Enterprise Security 07-29-2025
1 3
1
3
AliMaher
Hello Splunker,I hope you all are doing well.  I prepare to take the SPLK-3001 Exam, and I want to know the Self-Stud...
by AliMaher Path Finder in Splunk Enterprise Security 07-25-2025
0 2
0
2
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors