Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
vinz2020
Dear all I have an issue with a new dedicated Search Head for ES. My Splunk architecture is quite simple. 4 clustere...
by vinz2020 Explorer in Splunk Enterprise Security 07-29-2021
0 2
0
2
SamHTexas
I need to access these saved searches & change their timing due to them conflicting / running at the same time so man...
by SamHTexas Builder in Splunk Enterprise Security 07-27-2021
0 3
0
3
akshatj2
Hi All, We need to integrate MS SQL logs with Splunk. The current default add-on supports logs via DB Connect but we...
by akshatj2 Path Finder in Splunk Enterprise Security 07-27-2021
0 10
0
10
SamHTexas
I need to run a check on my Indexes making sure they are healthy. Where & how do I do it? Thank u very much in advanc...
by SamHTexas Builder in Splunk Enterprise Security 07-26-2021
0 2
0
2
stayready40
hello all I am fairly new to using Splunk and would like some help with searching for locked accounts and to Setup an...
by stayready40 Engager in Splunk Enterprise Security 07-26-2021
0 3
0
3
hettervik
Hi. I have some problems upgrading to Splunk ES 6.0. Normally I've just done the upgrade in the UI, no problem. Howe...
by SplunkTrust SplunkTrust in Splunk Enterprise Security 07-22-2021
4 6
4
6
SamHTexas
I need to provide HA & better performance in MC for the Enterprise Console (ES) what health check items in MC or DMC ...
by SamHTexas Builder in Splunk Enterprise Security 07-22-2021
0 0
0
0
VijaySrrie
Hi,User needs a link which has the splunk qurery and resultsHe wants to attach the link to already existing dashboard...
by VijaySrrie Builder in Splunk Enterprise Security 07-22-2021
0 1
0
1
VijaySrrie
Hi,I am forwarding sysmon logs to splunk, for normalization, I could see event ID : 12, 13, 14 are captured (Registry...
by VijaySrrie Builder in Splunk Enterprise Security 07-22-2021
0 1
0
1
hamidreza123
Hello my friends I had a problem for 2 days I am not allowed to search in Splank Thankful
by hamidreza123 New Member in Splunk Enterprise Security 07-21-2021
0 1
0
1
itssuresh07
Hi,Can someone help me in correlating 4688 Process created and Logon 4624 events?I tried using the Transaction  and S...
by itssuresh07 New Member in Splunk Enterprise Security 07-20-2021
0 2
0
2
oylkm
I want to integrate data from a Splunk App to the Vuln centre in Enterprise Security. Has anyone done this before?
by oylkm Explorer in Splunk Enterprise Security 07-19-2021
0 0
0
0
splunkeradmin22
Hi Everyone,I am trying to write a query that will allow me to use my notable_events table, display the time the nota...
by splunkeradmin22 New Member in Splunk Enterprise Security 07-16-2021
0 1
0
1
naregayam
Hi, I want to integrate emails from particular DL into splunk and splunk should create alerts for that traffic.
by naregayam New Member in Splunk Enterprise Security 07-15-2021
0 5
0
5
efika
An analyst adds a note to investigation. Another analyst from another shift delete this note.where is the audit trail...
by efika Communicator in Splunk Enterprise Security 07-15-2021
1 0
1
0
wtaylor149
I'm searching using the | rest command from search bar. Attempting to find saved searches that have been modified in...
by wtaylor149 Explorer in Splunk Enterprise Security 07-15-2021
0 2
0
2
lilian1009
Hi, I need to reinstall operation system for my computer installed splunk enterprise recently, and I want to backup t...
by lilian1009 New Member in Splunk Enterprise Security 07-14-2021
0 1
0
1
kagamalai
Hi,We have around the world 10 data centers each dc have the firewall setup, servers, splunk indexer. Headquarters ha...
by kagamalai Explorer in Splunk Enterprise Security 07-13-2021
0 0
0
0
splunkb0y
Hello, I got this query from Crowdstrike Documentation https[://]www[.]crowdstrike[. ]com/blog/tech-center/hunt-thre...
by splunkb0y New Member in Splunk Enterprise Security 07-13-2021
0 4
0
4
ctfletcher
Greetings Splunkers,I have a dashboard that "broke" over the weekend. When I run any of the dashboard searches I see ...
by ctfletcher New Member in Splunk Enterprise Security 07-13-2021
0 0
0
0
conma293
Not sure why this is so hard... Wana go back say 7/30/90 days and stats count number of alerts per analyst. Ie who cl...
by conma293 New Member in Splunk Enterprise Security 07-12-2021
0 1
0
1
SamHTexas
I have Indexer clustering, SH clustering in a distributed environment. 
by SamHTexas Builder in Splunk Enterprise Security 07-12-2021
0 2
0
2
palemmahesh
I want to fetch the results from triggered alerts  from time T1 to T2.Tried passing the earliest_time or earliest que...
by palemmahesh Engager in Splunk Enterprise Security 07-11-2021
0 1
0
1
VijaySrrie
Hi,For "Endpoint datamodel" with specific to "sysmon" sourcetype, what are all the mandatory fields?  
by VijaySrrie Builder in Splunk Enterprise Security 07-11-2021
0 1
0
1
kranthi1214
Hi, Anyone has this issue, Risk lists are limited to 100,000 rows in Splunk for recorded future. Any ideas?
by kranthi1214 New Member in Splunk Enterprise Security 07-09-2021
0 0
0
0
Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...