Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
evelenke
Hi Splunkers , any advice how to avoid mixng values in assets by entitymerge command? I have 5 fileds marked as Mult...
by evelenke Contributor in Splunk Enterprise Security 10-02-2020
1 1
1
1
cwo1010
Hello,I am trying to use Splunk's REST API in order to change portions of existing correlation searches created withi...
by cwo1010 Explorer in Splunk Enterprise Security 10-02-2020
0 4
0
4
danielbb
We enabled the TAXII feed and we see under Threat Intelligence Audit that the TAXII feed polling was starting. Where ...
by danielbb Motivator in Splunk Enterprise Security 10-02-2020
0 4
0
4
DawoodKhanUlex
Hi Folks,I want find all source and sourcetype for enable notables in Splunk ES.Please advise.Regards,D
by DawoodKhanUlex Engager in Splunk Enterprise Security 10-02-2020
0 2
0
2
MonkeyK
Can someone tell me what in the Authentication data model distinguishes between login and logout? http://docs.splunk....
by MonkeyK Builder in Splunk Enterprise Security 10-02-2020
1 5
1
5
LM_ACN
Hello everyone,i have a set of correlation search (about 250) to deploy in different Splunk ES.Instead of writing the...
by LM_ACN Engager in Splunk Enterprise Security 10-01-2020
0 2
0
2
chooglin
I have custom content that I've created in SSE and mapped to various parts of the MITRE Framework. The problem is SSE...
by chooglin Loves-to-Learn in Splunk Enterprise Security 09-30-2020
0 1
0
1
havatz
HiThis is my API AWS query:"search index=aws userIdentity.type=Root eventName=ConsoleLogin earliest=-10d  | rex field...
by havatz Explorer in Splunk Enterprise Security 09-29-2020
0 3
0
3
d_lim
My question is, how can I prove that the Splunk server.conf enableSplunkdSSL is indeed working and with the sslVersio...
by d_lim Path Finder in Splunk Enterprise Security 09-29-2020
0 4
0
4
Osvaldo91
Good day, I have noticed that the incident review shows no events, for about a day. The indexers were reviewed by m...
by Osvaldo91 Engager in Splunk Enterprise Security 09-28-2020
1 3
1
3
splunkcol
Has anyone presented this problem? 
by splunkcol Builder in Splunk Enterprise Security 09-28-2020
0 3
0
3
eriklp
Hi there, The situation is as follows. We've a scheduled search running which is doing LDAP query on Active directory...
by eriklp Explorer in Splunk Enterprise Security 09-25-2020
1 7
1
7
SabariRajanT
Can someone help me to identify Percentage of Indexes’ logs in 24 hours.?I have pulled using count like this :index=*...
by SabariRajanT Path Finder in Splunk Enterprise Security 09-23-2020
0 1
0
1
splunkcol
This warning message indicates that even though it has errors, it is still running or is definitely not working?Async...
by splunkcol Builder in Splunk Enterprise Security 09-22-2020
2 1
2
1
BenjaminWyatt
Hi everyone,   I have a request from our security team to reorder our notable event statuses in the dropdown. We have...
by BenjaminWyatt Communicator in Splunk Enterprise Security 09-21-2020
0 2
0
2
DanielSp
Hello,Do you know how I can put HttpOnly and Secure to true in cookie login?Security team request It to me.It happens...
by DanielSp Explorer in Splunk Enterprise Security 09-21-2020
1 2
1
2
jg91
Hello friends,We have Splunk ES and we stored our data in different indexes (OS logs, Network logs, ...)I have a ques...
by jg91 Path Finder in Splunk Enterprise Security 09-20-2020
1 1
1
1
thambisetty
When closing a notable event in SPLUNK Enterprise Security, there are typically the following fields available Status...
by SplunkTrust SplunkTrust in Splunk Enterprise Security 09-20-2020
1 4
1
4
alekwisnia
Enterprise Security has a nice Glass Table feature. I'm wondering if it is possible to include it within dashboard? O...
by alekwisnia Explorer in Splunk Enterprise Security 09-18-2020
0 2
0
2
ansusabu
I was trying to create a manual notable event using "sendalert notable". But the name of the notable is coming as "Ma...
by ansusabu Communicator in Splunk Enterprise Security 09-18-2020
0 4
0
4
malvidin
The Owner selection in Incident Review filters by the account "Full name", but the Investigations filter to add users...
by malvidin Communicator in Splunk Enterprise Security 09-16-2020
0 0
0
0
nareerat_pr
How can I set up an email alert to notify someone who is assigned the incident from the incident review page?
by nareerat_pr Explorer in Splunk Enterprise Security 09-16-2020
0 1
0
1
jogonz20
I am trying to figure out how I can track the timestamp whenever I changed the status of any recently opened investig...
by jogonz20 Explorer in Splunk Enterprise Security 09-14-2020
0 2
0
2
d_lim
Hi all,I'm having these error messages -Streamed seach execute failed beacuse: Error in 'lookup' command: Could not c...
by d_lim Path Finder in Splunk Enterprise Security 09-11-2020
0 1
0
1
venkasplunk
Hi all, Just installed splunk security essentials app and after that did a "Start Searches" , its running for long t...
by venkasplunk New Member in Splunk Enterprise Security 09-10-2020
0 3
0
3
Get Updates on the Splunk Community!

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...