Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
tomshew
I am trying to compare 2 indexes (malicious domains against proxy logs) using an evaluated field. I have a subsearch ...
by tomshew New Member in Splunk Enterprise Security 04-03-2020
0 7
0
7
Inayath_khan
Hi Folks, The incidents triggered in Splunk enterprise security are not getting replicated , i checked splunkd.log g...
by Inayath_khan Path Finder in Splunk Enterprise Security 04-03-2020
0 0
0
0
gwes77
Splunk has all of those threat intel lists for file, process, registry, ip, url, etc... And each list has a descrip...
by gwes77 Explorer in Splunk Enterprise Security 04-03-2020
1 0
1
0
jsven7
Situation: I have a panel. The panel creates a token for me from a field I extract from the search. In the same pane...
by jsven7 Communicator in Splunk Enterprise Security 04-03-2020
0 3
0
3
d4wc3k
Hello everyone I have following problem: I have set disabled flag in ip_intel by following query: | inputlookup ip_i...
by d4wc3k Path Finder in Splunk Enterprise Security 04-03-2020
0 0
0
0
virchenko
Hello all! I'm having trouble with Enterprise Security => Incident Review page. all time "Search is waiting for input...
by virchenko Explorer in Splunk Enterprise Security 04-02-2020
0 8
0
8
twh1
I am working with MS-Exchange data. I am taking recipient email value and matching with user lookup for other details...
by twh1 Communicator in Splunk Enterprise Security 04-02-2020
0 2
0
2
zekiramhi
Hello Fellow Splunkers, I have been trying the following query to pull the ES notified hosts and bring a sparkline o...
by zekiramhi Path Finder in Splunk Enterprise Security 04-01-2020
0 1
0
1
shannan2
In an attempt to bring in some additional Azure AD data we have begun using the Microsoft Azure Add-on for Splunk, ho...
by shannan2 Explorer in Splunk Enterprise Security 04-01-2020
1 1
1
1
rtalcik
| tstats count where index=proxy AND sourcetype=dns earliest=-7d by _time, ComputerName span=1h | xyseries _time, Com...
by rtalcik Path Finder in Splunk Enterprise Security 04-01-2020
0 4
0
4
mansourireza
I have the following scheduled search that updates a lookup (simple_identity_lookup) by adding new entries that aren'...
by mansourireza Explorer in Splunk Enterprise Security 04-01-2020
1 2
1
2
brownt61
Hello, I am attempting to create a workflow action that allows a risk modifier to be adjusted. I have the command n...
by brownt61 Explorer in Splunk Enterprise Security 04-01-2020
0 0
0
0
rtalcik
How do I go about editing the data have the data from umbrella dns logs update the network resolution dns data model
by rtalcik Path Finder in Splunk Enterprise Security 03-31-2020
0 0
0
0
georgemak
Hello, I've been using Splunk for less than a year and I'm trying to know how to size Splunk deployment(hardware req...
by georgemak Engager in Splunk Enterprise Security 03-31-2020
0 3
0
3
jsven7
Situation: - I have some records with a human readable field "Creation Date" (MM/DD/YYYY HH:MM:SS). - I'd like to so...
by jsven7 Communicator in Splunk Enterprise Security 03-31-2020
0 2
0
2
mpham07
Hello all, I'm currently stumped in trying to figure out why my notable event token is not working. I verified the ...
by mpham07 Path Finder in Splunk Enterprise Security 03-31-2020
0 8
0
8
vishwanath119
Need to read from all files present in /temp/logs/ directory except one file abc.log Directory looks like xyz.log ab...
by vishwanath119 New Member in Splunk Enterprise Security 03-31-2020
0 3
0
3
mmqt
I'm trying to figure out what provides data to the inputlookup:system_version_tracker for ES. Currently its only popu...
by mmqt Path Finder in Splunk Enterprise Security 03-31-2020
1 1
1
1
shravankumarkus
How do we write search query to get notable events based on last modified time for a correlation rule ? I want to se...
by shravankumarkus New Member in Splunk Enterprise Security 03-30-2020
0 9
0
9
Ankush_Kumar
Hi Community members. I need your help to identify where I am doing wrong in regex field extraction. Actually there...
by Ankush_Kumar New Member in Splunk Enterprise Security 03-30-2020
0 5
0
5
bansodesant
I was removing different application and accidentally removed these Splunk ES supported and other application. It wil...
by bansodesant Explorer in Splunk Enterprise Security 03-30-2020
0 0
0
0
Ankush_Kumar
Hi Team, My question is i have antivirus events and firewall traffic and i want to run antivirus search as a subsear...
by Ankush_Kumar New Member in Splunk Enterprise Security 03-30-2020
0 8
0
8
jerm1020rq
When searching for sourcetype=recorded future IOCS, i receive the following error. I updated the API key and that fix...
by jerm1020rq Explorer in Splunk Enterprise Security 03-29-2020
0 1
0
1
rtalcik
What my search is trying to do is whenever the search matches an item in the lookup list it should display the result...
by rtalcik Path Finder in Splunk Enterprise Security 03-27-2020
0 3
0
3
miguelangelclem
Hi all, I have a distributed multisite architecture, with a single Search Head, 2 indexers and, 2 Forwarders a Clust...
by miguelangelclem Explorer in Splunk Enterprise Security 03-27-2020
0 4
0
4
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...