Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
Azeemering
Hi,I'm trying to upload a simple list of malicious filenames into ES Threat Intel.I have a csv file which I formatted...
by Azeemering Builder in Splunk Enterprise Security 09-20-2021
1 2
1
2
paola92
I tried to retrieve assets information of ldap so I used the search (I know that I must not to use search nt_host...)...
by paola92 Explorer in Splunk Enterprise Security 09-19-2021
0 4
0
4
zyun
We're currently using Splunk ES, and would like to grab the link to a notable event's drilldown link on the ES Incide...
by zyun Explorer in Splunk Enterprise Security 09-17-2021
0 1
0
1
securitypaul
Hello! Can anyone please lend a hand with this issue? I'm still fairly new to this and am working my way through Fund...
by securitypaul Explorer in Splunk Enterprise Security 09-17-2021
0 3
0
3
sayantabasak
Hello, I wanted to reach out to you for assistance on Splunk ES threat_intel searches. Objective: We have endpoint ...
by sayantabasak Explorer in Splunk Enterprise Security 09-17-2021
1 1
1
1
mjgeneroso
Hi,I want to set  up my 7-day trial Splunk Enterprise Security Sandbox. But when I click the start trial. I am gettin...
by mjgeneroso New Member in Splunk Enterprise Security 09-17-2021
0 0
0
0
dokaas_2
I'm in the process of implementing Splunk ES.  We are using the Splunk_TA_windows and use the generate_windows_update...
by dokaas_2 Communicator in Splunk Enterprise Security 09-16-2021
0 0
0
0
xnx_1012
Hi,Based on my understanding, from the Splunk Guide, https://docs.splunk.com/Documentation/ES/6.6.0/Admin/Configureco...
by xnx_1012 Explorer in Splunk Enterprise Security 09-16-2021
0 6
0
6
xnx_1012
Hi to whomever find thisThe incident management review settings has repeated eventsWhat I did?I purpose logged in wit...
by xnx_1012 Explorer in Splunk Enterprise Security 09-15-2021
0 0
0
0
vr2312
After building a project/add-on based on the Standard naming convention of Splunk, i am facing the issue where i have...
by vr2312 Builder in Splunk Enterprise Security 09-15-2021
0 2
0
2
soumyasaha25
I would have to move my custom Correlation rules  to a custom TA-foo appMy correlation searches comprises of:custom r...
by soumyasaha25 Contributor in Splunk Enterprise Security 09-15-2021
0 1
0
1
hperez
I created a correlation search with only two pipes, table and rename. I added inline table to the email notification ...
by hperez Explorer in Splunk Enterprise Security 09-13-2021
0 1
0
1
b_chris21
Hello all,I am struggling with customizing my Splunk ES's Incident Review panel. I have integrated Suricata IDS logs ...
by b_chris21 Communicator in Splunk Enterprise Security 09-13-2021
0 1
0
1
SamHTexas
I am getting started using DS to deploy new configurations to UFs. Need to view the list of Server classes , what the...
by SamHTexas Builder in Splunk Enterprise Security 09-13-2021
0 2
0
2
canalesjac
I’m running VMWare Horizon View 7 in my organization. Now with COVID-19 Shelter in place we all need to WFH. How do I...
by canalesjac Path Finder in Splunk Enterprise Security 09-10-2021
3 13
3
13
SamHTexas
I notice some include .csv files. Do these .csv s need updating? Or do they stay stale? How are Data sets updated? Pl...
by SamHTexas Builder in Splunk Enterprise Security 09-10-2021
0 3
0
3
stwong
Hi all,Just note that the macro 'cim_Authentication_indexes` of Splunk_SA_CIM has definition like following:[cim_Auth...
by stwong Communicator in Splunk Enterprise Security 09-09-2021
0 6
0
6
xnx_1012
Hello, Whenever I tried to create a notable event by "Configure -> Incident Management -> New Notable Event", the web...
by xnx_1012 Explorer in Splunk Enterprise Security 09-09-2021
0 0
0
0
vamshikn72
Hello Splunkers, I am looking for an html page in a dashboard with ID, ID_Name, an other fields with Text box, dropdo...
by vamshikn72 Explorer in Splunk Enterprise Security 09-08-2021
0 0
0
0
akashsaxena454
How can  I integrate Trend micro apex one with Splunk Enterprise?
by akashsaxena454 New Member in Splunk Enterprise Security 09-08-2021
0 0
0
0
saharzare
I see this :/opt/splunk/etc/apps/splunk_essentials_8_2/appserver/static/exampleInfo.jsondiffers/opt/splunk/etc/apps/s...
by saharzare Engager in Splunk Enterprise Security 09-07-2021
0 1
0
1
momomok
Hi,Ever since upgrading to ES 6.2, there has been a problem bugging our team.Whenever we select one of the notable ev...
by momomok Loves-to-Learn in Splunk Enterprise Security 09-05-2021
0 0
0
0
StanD3sec
I can CRUD threat intel collection rows with ESS REST API(such as /services/data/threat_intel/item/ip_intel), and I c...
by StanD3sec Loves-to-Learn in Splunk Enterprise Security 09-03-2021
0 0
0
0
SamHTexas
Need help with KVstore status. Why do I get "This health check item is not applicable" in MC in my ES while I have ma...
by SamHTexas Builder in Splunk Enterprise Security 09-03-2021
0 1
0
1
inayath_khanin1
Identity: 314 assets are currently exceeding the field limits set in the Asset and Identity Management page. Data tru...
by inayath_khanin1 Explorer in Splunk Enterprise Security 09-03-2021
0 2
0
2
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...
Top Solution Authors