Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
Laszlo_K
Enabled 3 ESCU rules in ES and mapped them in SSE using Content Introspection on the Manage Bookmarks page.After a Re...
by Laszlo_K Explorer in Splunk Enterprise Security 09-02-2020
0 0
0
0
abhinav_go
Hi ,Can anyone provide me approach/steps for integrating threat intelligence framework to Splunk ES.Also , how to pul...
by abhinav_go Explorer in Splunk Enterprise Security 09-01-2020
1 0
1
0
jaracan
Hi Team,We are planning to upgrade from Splunk Enterprise v7.2.9.1 to Splunk Enterprise v8.0.x on the next few months...
by jaracan Communicator in Splunk Enterprise Security 09-01-2020
0 1
0
1
enugeelumpfz
Hi Everyone, We have Suricata NIDS onboard and plans to integrate with Splunk and in particular with Splunk Enterpri...
by enugeelumpfz Engager in Splunk Enterprise Security 08-31-2020
1 5
1
5
diptij
I had converted my Splunk Head to use SSL.I added /opt/splunk/etc/system/local/web.conf and updated [settings] to put...
by diptij Path Finder in Splunk Enterprise Security 08-31-2020
0 2
0
2
moshahin
Hi,I've been trying to get email trace for office365 exchange using the addon in subject. No data is coming under thi...
by moshahin Engager in Splunk Enterprise Security 08-31-2020
1 0
1
0
ak9092
Hi,I have a transaction that goes through multiple Status before its completed.Now the challenge I am facing here is ...
by ak9092 Path Finder in Splunk Enterprise Security 08-31-2020
0 2
0
2
GOB_Bluth
We would like to dynamically assign an owner of a notable event? Our soc would like to round robin the incoming eve...
by GOB_Bluth Explorer in Splunk Enterprise Security 08-30-2020
0 5
0
5
AK007
Hi, We have correlation search with action as notable. Initially we made it low Severity on notable to monitor and se...
by AK007 Engager in Splunk Enterprise Security 08-29-2020
0 3
0
3
Thor1
How to get a complete list with descriptions of correlation searches in the Splunk Enterprise Security app with sourc...
by Thor1 New Member in Splunk Enterprise Security 08-29-2020
0 2
0
2
nmcdowell
I have set up an alert for when logging has stopped on a Windows endpoint using event code 1100, but want to avoid re...
by nmcdowell New Member in Splunk Enterprise Security 08-28-2020
0 3
0
3
danielbb
For our accelerated datamodels,  acceleration.max_concurrent is set to 3 and we reach situations where lots of cpu is...
by danielbb Motivator in Splunk Enterprise Security 08-27-2020
0 2
0
2
shayhibah
Hey,I have one sourcetype named "my_sourcetype".Since I would like to integrate with Splunk ES, I need to map my fiel...
by shayhibah Path Finder in Splunk Enterprise Security 08-27-2020
0 1
0
1
kbrazil899
I am trying to configure SecKit with ES 6.1.1 but I am running into an issue with the configuration I am hoping someo...
by kbrazil899 New Member in Splunk Enterprise Security 08-26-2020
0 1
0
1
majid87
Hello,Im no longer able to retrieve historical data from inputlookup incident_review_lookup . When i check the lookup...
by majid87 Engager in Splunk Enterprise Security 08-26-2020
0 0
0
0
Bassik
Hi, I want to be able to visualise the top 1-5/10 login times based on a time range. So if I select a time range of 2...
by Bassik Path Finder in Splunk Enterprise Security 08-26-2020
0 3
0
3
duoms
Hi, Is there any tools to visualize data lineage in splunk ? https://en.wikipedia.org/wiki/Data_lineage We would like...
by duoms New Member in Splunk Enterprise Security 08-25-2020
0 1
0
1
BenzSann
ES 6.0.2 is python 2/3 but in the Release Notes: “However, this release is not completely dual Python 2 and Python 3 ...
by BenzSann Splunk Employee Splunk Employee in Splunk Enterprise Security 08-24-2020
0 2
0
2
sreedharmallemp
hi all,We are not able to add any other colleagues as collaborator for the invetsigations. Can someone please help me...
by sreedharmallemp Explorer in Splunk Enterprise Security 08-24-2020
0 1
0
1
phanichintha
Hello All,In my organisation, the Nessus scanner scans the Splunk servers and other application servers. Scanner foun...
by phanichintha Path Finder in Splunk Enterprise Security 08-24-2020
0 1
0
1
shayhibah
Hi,In my logs I have the field name action.This field can have several values: allow, detect, block and etc.Since I w...
by shayhibah Path Finder in Splunk Enterprise Security 08-20-2020
0 3
0
3
splunkcol
The following error appears "The number of search artifacts in the dispatch directory is higher than recommended (cou...
by splunkcol Builder in Splunk Enterprise Security 08-19-2020
0 2
0
2
splunky33212
Hello,Is there any RHEL 7 End of Life and End of Support Dates? For additional info, we are using software version 8....
by splunky33212 New Member in Splunk Enterprise Security 08-18-2020
0 1
0
1
nbr
I am getting attached error while configuring Splunk Event Ingestion integration in Servicenow. -> verified the commu...
by nbr Explorer in Splunk Enterprise Security 08-17-2020
0 0
0
0
devsplunk11
Hello Team, I am getting error "Invalid account error when trying to access ES Sandbox instance URL?" ThanksLalit
by devsplunk11 New Member in Splunk Enterprise Security 08-16-2020
0 0
0
0
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...
Top Solution Authors