Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
nareerat_pr
How can I set up an email alert to notify someone who is assigned the incident from the incident review page?
by nareerat_pr Explorer in Splunk Enterprise Security 09-16-2020
0 1
0
1
jogonz20
I am trying to figure out how I can track the timestamp whenever I changed the status of any recently opened investig...
by jogonz20 Explorer in Splunk Enterprise Security 09-14-2020
0 2
0
2
d_lim
Hi all,I'm having these error messages -Streamed seach execute failed beacuse: Error in 'lookup' command: Could not c...
by d_lim Path Finder in Splunk Enterprise Security 09-11-2020
0 1
0
1
venkasplunk
Hi all, Just installed splunk security essentials app and after that did a "Start Searches" , its running for long t...
by venkasplunk New Member in Splunk Enterprise Security 09-10-2020
0 3
0
3
saotaigiri
Please I am looking for a query to search for the top alerts that fired within 2 weeks (or within a time frame).I am ...
by saotaigiri Path Finder in Splunk Enterprise Security 09-10-2020
0 1
0
1
ololdach
Hi fellow Splunkers, I've stumbled upon a cool piece of code, namely the ASX app that allows you to load configuratio...
by ololdach Builder in Splunk Enterprise Security 09-10-2020
0 0
0
0
alekwisnia
I need an action for an incident responder to send a selected event's data via email. I can define notable actions, b...
by alekwisnia Explorer in Splunk Enterprise Security 09-10-2020
0 1
0
1
Splunkometry88
Hi TeamI am searching to confirm the SPL to poll a KV Store check the status of the es_notable_events when a status c...
by Splunkometry88 Explorer in Splunk Enterprise Security 09-10-2020
0 3
0
3
d_lim
Hello, so I was looking at my metadata/local.meta and it is only the following 4 lines:[savedsearches/mysavedsearch]o...
by d_lim Path Finder in Splunk Enterprise Security 09-09-2020
0 3
0
3
armanih
Hi All,I have two indexes.Index A | table email_usersIndex B | table email, Groupemail_users and email fields contain...
by armanih Explorer in Splunk Enterprise Security 09-08-2020
0 3
0
3
FranziskaHodbod
I would like to integrate an app or add-on into Splunk that enables employees in the company to bring anomalies into ...
by FranziskaHodbod New Member in Splunk Enterprise Security 09-08-2020
0 1
0
1
mounavignesh
I'm not able to search cloud-front logs from S3. There is no results. But I'm able to search ELB logs and Cloud-trail...
by mounavignesh New Member in Splunk Enterprise Security 09-07-2020
0 0
0
0
nareerat_pr
I've created a correlation search, then I want to add the send email response action with a link to this rule that sh...
by nareerat_pr Explorer in Splunk Enterprise Security 09-07-2020
0 1
0
1
josephliion
Hi there, I noticed that the URL path for the MaxMind ASN Database has changed on, to another path, and the siem can ...
by josephliion Explorer in Splunk Enterprise Security 09-04-2020
3 7
3
7
Splunkometry88
Hi TeamI am looking to send an email alert once the notable event is closed, I can send an email when the notable eve...
by Splunkometry88 Explorer in Splunk Enterprise Security 09-04-2020
0 1
0
1
jadengoho
Why do we encounter this  "Does not meet the recommended minimum system"  only for ESSH03 even though all of the syst...
by jadengoho Builder in Splunk Enterprise Security 09-04-2020
0 3
0
3
Splunkometry88
Hi allI have a threat feed that is available via using an API key only, I could not see any way to add the API key to...
by Splunkometry88 Explorer in Splunk Enterprise Security 09-04-2020
0 1
0
1
astatrial
Hi everyone,Introduction:We have Palo Alto products, and we have also installed the appropriate add-on and apps. We m...
by astatrial Contributor in Splunk Enterprise Security 09-03-2020
0 2
0
2
vik_splunk
Hi All,We notice a seemingly weird behaviour where modifying the notable severity in a correlation search brings up h...
by vik_splunk Communicator in Splunk Enterprise Security 09-02-2020
0 6
0
6
Laszlo_K
Enabled 3 ESCU rules in ES and mapped them in SSE using Content Introspection on the Manage Bookmarks page.After a Re...
by Laszlo_K Explorer in Splunk Enterprise Security 09-02-2020
0 0
0
0
abhinav_go
Hi ,Can anyone provide me approach/steps for integrating threat intelligence framework to Splunk ES.Also , how to pul...
by abhinav_go Explorer in Splunk Enterprise Security 09-01-2020
1 0
1
0
jaracan
Hi Team,We are planning to upgrade from Splunk Enterprise v7.2.9.1 to Splunk Enterprise v8.0.x on the next few months...
by jaracan Communicator in Splunk Enterprise Security 09-01-2020
0 1
0
1
enugeelumpfz
Hi Everyone, We have Suricata NIDS onboard and plans to integrate with Splunk and in particular with Splunk Enterpri...
by enugeelumpfz Engager in Splunk Enterprise Security 08-31-2020
1 5
1
5
diptij
I had converted my Splunk Head to use SSL.I added /opt/splunk/etc/system/local/web.conf and updated [settings] to put...
by diptij Path Finder in Splunk Enterprise Security 08-31-2020
0 2
0
2
moshahin
Hi,I've been trying to get email trace for office365 exchange using the addon in subject. No data is coming under thi...
by moshahin Engager in Splunk Enterprise Security 08-31-2020
1 0
1
0
Get Updates on the Splunk Community!

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors