Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
SabariRajanT
Can someone help me to identify Percentage of Indexes’ logs in 24 hours.?I have pulled using count like this :index=*...
by SabariRajanT Path Finder in Splunk Enterprise Security 09-23-2020
0 1
0
1
splunkcol
This warning message indicates that even though it has errors, it is still running or is definitely not working?Async...
by splunkcol Builder in Splunk Enterprise Security 09-22-2020
2 1
2
1
BenjaminWyatt
Hi everyone,   I have a request from our security team to reorder our notable event statuses in the dropdown. We have...
by BenjaminWyatt Communicator in Splunk Enterprise Security 09-21-2020
0 2
0
2
DanielSp
Hello,Do you know how I can put HttpOnly and Secure to true in cookie login?Security team request It to me.It happens...
by DanielSp Explorer in Splunk Enterprise Security 09-21-2020
1 2
1
2
jg91
Hello friends,We have Splunk ES and we stored our data in different indexes (OS logs, Network logs, ...)I have a ques...
by jg91 Path Finder in Splunk Enterprise Security 09-20-2020
1 1
1
1
thambisetty
When closing a notable event in SPLUNK Enterprise Security, there are typically the following fields available Status...
by SplunkTrust SplunkTrust in Splunk Enterprise Security 09-20-2020
1 4
1
4
alekwisnia
Enterprise Security has a nice Glass Table feature. I'm wondering if it is possible to include it within dashboard? O...
by alekwisnia Explorer in Splunk Enterprise Security 09-18-2020
0 2
0
2
ansusabu
I was trying to create a manual notable event using "sendalert notable". But the name of the notable is coming as "Ma...
by ansusabu Communicator in Splunk Enterprise Security 09-18-2020
0 4
0
4
malvidin
The Owner selection in Incident Review filters by the account "Full name", but the Investigations filter to add users...
by malvidin Communicator in Splunk Enterprise Security 09-16-2020
0 0
0
0
nareerat_pr
How can I set up an email alert to notify someone who is assigned the incident from the incident review page?
by nareerat_pr Explorer in Splunk Enterprise Security 09-16-2020
0 1
0
1
jogonz20
I am trying to figure out how I can track the timestamp whenever I changed the status of any recently opened investig...
by jogonz20 Explorer in Splunk Enterprise Security 09-14-2020
0 2
0
2
d_lim
Hi all,I'm having these error messages -Streamed seach execute failed beacuse: Error in 'lookup' command: Could not c...
by d_lim Path Finder in Splunk Enterprise Security 09-11-2020
0 1
0
1
venkasplunk
Hi all, Just installed splunk security essentials app and after that did a "Start Searches" , its running for long t...
by venkasplunk New Member in Splunk Enterprise Security 09-10-2020
0 3
0
3
saotaigiri
Please I am looking for a query to search for the top alerts that fired within 2 weeks (or within a time frame).I am ...
by saotaigiri Path Finder in Splunk Enterprise Security 09-10-2020
0 1
0
1
ololdach
Hi fellow Splunkers, I've stumbled upon a cool piece of code, namely the ASX app that allows you to load configuratio...
by ololdach Builder in Splunk Enterprise Security 09-10-2020
0 0
0
0
alekwisnia
I need an action for an incident responder to send a selected event's data via email. I can define notable actions, b...
by alekwisnia Explorer in Splunk Enterprise Security 09-10-2020
0 1
0
1
Splunkometry88
Hi TeamI am searching to confirm the SPL to poll a KV Store check the status of the es_notable_events when a status c...
by Splunkometry88 Explorer in Splunk Enterprise Security 09-10-2020
0 3
0
3
d_lim
Hello, so I was looking at my metadata/local.meta and it is only the following 4 lines:[savedsearches/mysavedsearch]o...
by d_lim Path Finder in Splunk Enterprise Security 09-09-2020
0 3
0
3
armanih
Hi All,I have two indexes.Index A | table email_usersIndex B | table email, Groupemail_users and email fields contain...
by armanih Explorer in Splunk Enterprise Security 09-08-2020
0 3
0
3
FranziskaHodbod
I would like to integrate an app or add-on into Splunk that enables employees in the company to bring anomalies into ...
by FranziskaHodbod New Member in Splunk Enterprise Security 09-08-2020
0 1
0
1
mounavignesh
I'm not able to search cloud-front logs from S3. There is no results. But I'm able to search ELB logs and Cloud-trail...
by mounavignesh New Member in Splunk Enterprise Security 09-07-2020
0 0
0
0
nareerat_pr
I've created a correlation search, then I want to add the send email response action with a link to this rule that sh...
by nareerat_pr Explorer in Splunk Enterprise Security 09-07-2020
0 1
0
1
josephliion
Hi there, I noticed that the URL path for the MaxMind ASN Database has changed on, to another path, and the siem can ...
by josephliion Explorer in Splunk Enterprise Security 09-04-2020
3 7
3
7
Splunkometry88
Hi TeamI am looking to send an email alert once the notable event is closed, I can send an email when the notable eve...
by Splunkometry88 Explorer in Splunk Enterprise Security 09-04-2020
0 1
0
1
jadengoho
Why do we encounter this  "Does not meet the recommended minimum system"  only for ESSH03 even though all of the syst...
by jadengoho Builder in Splunk Enterprise Security 09-04-2020
0 3
0
3
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...