Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
erikhansen29
Hi All. Hopefully somebody has an answer to this.We are on v8.1.6 and in doing some security cleanup, I was removing ...
by erikhansen29 New Member in Splunk Enterprise Security 11-30-2021
0 0
0
0
SIEMStudent
Hi Splunkers,I'm in trouble with a correlation rule creation.The purposes of the rule is the following one: if a User...
by SIEMStudent Path Finder in Splunk Enterprise Security 11-30-2021
0 0
0
0
soumyasaha25
I have disabled a few of the Correlation searches and would like to delete them from the "Top Notable Events" panel i...
by soumyasaha25 Contributor in Splunk Enterprise Security 11-29-2021
0 0
0
0
comantxe
Hello,I just configured a new Custom Threat Intelligence feed in Splunk Enterprise Security and I'm getting a strange...
by comantxe New Member in Splunk Enterprise Security 11-24-2021
0 0
0
0
SamHTexas
Please help me with learning What dependencies dose Splunk Security Essentials App (SSE) has on ES & ES content updat...
by SamHTexas Builder in Splunk Enterprise Security 11-24-2021
0 0
0
0
Stefanie
Hey!We upgraded to Splunk Enterprise Security to the latest version a few weeks ago.Before, it was on Version 4.x I b...
by Stefanie Builder in Splunk Enterprise Security 11-23-2021
0 1
0
1
Prachi_Kothari
Hello, Hope you are  doing well!I have updated exiting correlation alert in Splunk as  notable event which previously...
by Prachi_Kothari Engager in Splunk Enterprise Security 11-22-2021
0 1
0
1
cybersej
Hi Everyone, I set splunk(on windows) lab envirement because try something threat activity.I need to take powershell ...
by cybersej Observer in Splunk Enterprise Security 11-22-2021
0 0
0
0
jacqu3sy
Hi, Within Splunk Enterprise Security, when the urgency of a notable event is calculated, the priority of the identi...
by jacqu3sy Path Finder in Splunk Enterprise Security 11-16-2021
0 7
0
7
damode
Does ES also comes with SSE app features like Analytics Advisor, Content Recommendations, Data inventory, CIM complia...
by damode Motivator in Splunk Enterprise Security 11-15-2021
0 3
0
3
pchintha
HI,I am having some logs comes with XML format for Privilaged Access Manager, i need to extract the fields by default...
by pchintha Engager in Splunk Enterprise Security 11-14-2021
0 0
0
0
HA-01
I tried to get data using Google Workspace Add-on, but the following error occurs. Could you please tell me how to re...
by HA-01 Splunk Employee Splunk Employee in Splunk Enterprise Security 11-14-2021
0 2
0
2
SIEMStudent
Hi everybody.Currently, we have a task which involve QRadar correlation rules translation to SPlunk ones.The Splunk r...
by SIEMStudent Path Finder in Splunk Enterprise Security 11-12-2021
0 0
0
0
NightShark
I have a problem where an admin role user cannot see another analyst user to assign specific notable events to. Howev...
by NightShark Path Finder in Splunk Enterprise Security 11-12-2021
0 1
0
1
So76
Hey, has anyone created a search that merges an ipadd from threat intel and ipadd from azure so it'll trigger an aler...
by So76 Explorer in Splunk Enterprise Security 11-12-2021
1 1
1
1
cfcvendorsuppor
Hello, I'm trying to force an app to use python 2.7 on a Splunk 8 with enterprise security. The config in server.co...
by cfcvendorsuppor Explorer in Splunk Enterprise Security 11-11-2021
1 9
1
9
gkeller
Hi everyone,We're using the Splunk Python SDK to run queries in Splunk.However, we seem to be getting the results in ...
by gkeller Explorer in Splunk Enterprise Security 11-10-2021
1 1
1
1
prashant_001
I have list of servers, I need a query to check whether splunk is getting data from the server or not ??
by prashant_001 Observer in Splunk Enterprise Security 11-10-2021
0 1
0
1
kanam
I install Splunk ES v5.3.1 on Enterprise v7.3.7.1, then I want to open "Incident Review".However the page has been lo...
by kanam Loves-to-Learn Everything in Splunk Enterprise Security 11-08-2021
0 1
0
1
andrew_burnett
What happened to the ES Sandbox? I can no longer find it to sign up for it.
by andrew_burnett Path Finder in Splunk Enterprise Security 11-08-2021
0 0
0
0
neerajs_81
Hello,I have followed https://docs.splunk.com/Documentation/ES/6.6.2/Admin/Customizenotables and created Additional F...
by neerajs_81 Builder in Splunk Enterprise Security 11-05-2021
1 1
1
1
woodentree
Hello, For internal control, we have to monitor all deactivations and all suppressions of correlation searches. Unfo...
by woodentree Communicator in Splunk Enterprise Security 11-05-2021
1 2
1
2
sheenay
Hey Guys, We are in a Splunk Cloud environment with ES, and we have added our own TAXII feed as well as some open sou...
by sheenay Explorer in Splunk Enterprise Security 11-04-2021
1 3
1
3
PickleRick
After restarting splunk master node machine (whole machine - there was no update of the splunk software itself, just ...
by SplunkTrust SplunkTrust in Splunk Enterprise Security 11-04-2021
0 0
0
0
SamHTexas
ES erroring reg. The latest threat list can not be downloaded. I visited the site it is trying to access manually , n...
by SamHTexas Builder in Splunk Enterprise Security 11-02-2021
0 1
0
1
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...