Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
RK_sp1unk
Splunk Enterprise security version 6 having issues we get the errors in incident review with the SA-Threat Intelli...
by RK_sp1unk New Member in Splunk Enterprise Security 02-19-2020
0 0
0
0
avni26
Hi, I'm trying to create a alert action to create a incident when any alert gets triggered. Whats the best way to a...
by avni26 Explorer in Splunk Enterprise Security 02-19-2020
0 3
0
3
twh1
I have some saved Splunk reports. I am calling these reports every hour by JAVA API call. If any hour due to some iss...
by twh1 Communicator in Splunk Enterprise Security 02-18-2020
0 0
0
0
vdeomampo12
Hi All, I have this issue that device is not logging to splunk. When I checked the splunkd.log I have found this err...
by vdeomampo12 New Member in Splunk Enterprise Security 02-18-2020
0 0
0
0
rtoloczk
Does the Phantom Remote Search app get installed on my Enterprise Security Search Head, a HEC server, or another serv...
by rtoloczk Explorer in Splunk Enterprise Security 02-18-2020
1 2
1
2
mjjohnson3
Does Splunk offer any additional courses for government personnel? Kind Regards, Mike
by mjjohnson3 New Member in Splunk Enterprise Security 02-18-2020
0 2
0
2
tan_junyuan
From my threat intel source, we tried to forward the intelligence source to Splunk ES-> Threat Intelligence The raw ...
by tan_junyuan Engager in Splunk Enterprise Security 02-17-2020
0 0
0
0
sumchan
How to customize the ES Incident Review in a way: 1) Once logged in, users can only see the Incident Review Dashboard...
by sumchan Engager in Splunk Enterprise Security 02-17-2020
1 0
1
0
adalbor
Hey All, We are planning on moving all of our UF's to the low priv mode install but I had a question. Our current U...
by adalbor Builder in Splunk Enterprise Security 02-17-2020
0 2
0
2
bsuresh1
Palo Alto firewall device (IPS and IDS only) is sending logs to rsyslog server and it gets saved in a directory. The...
by bsuresh1 Path Finder in Splunk Enterprise Security 02-15-2020
1 4
1
4
spodda01da
Hello All, I have been going through Multiple posts but still not able to configure my Splunk Add-on for Cisco ESA. ...
by spodda01da Path Finder in Splunk Enterprise Security 02-14-2020
0 0
0
0
carlangas93
Good Morning, I am implementing Infoblox logs in Splunk and it is giving me problems. I have 3 Splunk machines, one ...
by carlangas93 New Member in Splunk Enterprise Security 02-14-2020
0 0
0
0
danielbb
The cim validator shows the signature field as a recommended field for the Authentication datamodel while the followi...
by danielbb Motivator in Splunk Enterprise Security 02-12-2020
1 2
1
2
cody_richardson
Hello all, I'm currently trying to send AWS GuardDuty logs to Splunk and am hoping someone here can help. I'm using...
by cody_richardson Path Finder in Splunk Enterprise Security 02-12-2020
0 3
0
3
alexspunkshell
Unable to distribute to peer named xxxxxx at uri=xxxxxxxx:8089 using the uri-scheme=https because peer has status=2. ...
by alexspunkshell Contributor in Splunk Enterprise Security 02-12-2020
0 1
0
1
sonydrew
I have data from a couple different sources that I am trying to combine together into coherent results. The issue I a...
by sonydrew Explorer in Splunk Enterprise Security 02-12-2020
0 8
0
8
danan5
Hi, Does anyone happen to know if Multisite search head clustering is suppported in ES 6.x? The validated architectu...
by danan5 Path Finder in Splunk Enterprise Security 02-12-2020
0 1
0
1
mteverest
Hi, I have a scheduled search in Splunk with the following link in the description field [1] and would like to captur...
by mteverest New Member in Splunk Enterprise Security 02-12-2020
0 3
0
3
ajiwanand
We are deploying Enterprise Security for various clients on AWS, and are in the planning phase. I am attempting to cr...
by ajiwanand Path Finder in Splunk Enterprise Security 02-11-2020
0 0
0
0
jgdixon
We have gone through several weeks of trying to setup a solution to ingest sign-in logs. After finally getting what ...
by jgdixon New Member in Splunk Enterprise Security 02-11-2020
0 4
0
4
woodentree
Hello, In Enterprise Security's Asset Center I'd like to create a new field called "Comment". The goal is to fill it...
by woodentree Communicator in Splunk Enterprise Security 02-11-2020
0 2
0
2
dpandey
The logs sources push logs through SFTP but they are not readable or kind of logs are in encrypted form when receive...
by dpandey New Member in Splunk Enterprise Security 02-10-2020
0 5
0
5
richardphung
Symptom: Our authentication datamodel is showing user=Unknown for events that have a username defined in the log. Ex...
by richardphung Communicator in Splunk Enterprise Security 02-10-2020
0 15
0
15
RK_sp1unk
Getting an XML error while trying to install Splunk Enterprise security app splunk enterprise version:8.0 splunk ES ...
by RK_sp1unk New Member in Splunk Enterprise Security 02-10-2020
0 0
0
0
astatrial
Hi all, I am having major issues with creating drilldown to correlation searches, using tokens of the process paths...
by astatrial Contributor in Splunk Enterprise Security 02-10-2020
0 0
0
0
Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...