Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
tommoore
I'm hoping someone can assist me with this strange issue. For some reason my menu bar for enterprise security is gon...
by tommoore Path Finder in Splunk Enterprise Security 11-13-2019
0 6
0
6
prasanthkota
Hello All, I wanted to know if anyone has tried to modify whois to use cisco umbrella instead of domain tools?
by prasanthkota Engager in Splunk Enterprise Security 11-13-2019
0 0
0
0
swright_rl
Hi, I'm trying to add an additional condition to this rule. Currently it splits up the raw value from our web logs ...
by swright_rl Explorer in Splunk Enterprise Security 11-13-2019
0 3
0
3
Arpmjdr
Hi Friends, I am using SPLUNK ES 5.3.1 version.I am trying to validate the existing datamodels(Total 32 including ci...
by Arpmjdr Explorer in Splunk Enterprise Security 11-13-2019
0 3
0
3
danielbb
The bluecloat sourcetype "bluecoat:proxysg:admin:file" is tagged as error. It's also not listed at Sourcetypes for th...
by danielbb Motivator in Splunk Enterprise Security 11-13-2019
0 2
0
2
bsuresh1
Hi All, Environment: Splunk Cloud We have installed "Fortinet Fortigate Add-On for Splunk" on our Onprem Heavy Forw...
by bsuresh1 Path Finder in Splunk Enterprise Security 11-12-2019
0 4
0
4
mikeyph
I'm trying to unify records from two different indexes, as part of this I'm trying to create a common field by extrac...
by mikeyph New Member in Splunk Enterprise Security 11-12-2019
0 1
0
1
abhi04
How to add a site into action fields in Splunk Enterprise Security? We have nslookup, google search,etc added as part...
by abhi04 Communicator in Splunk Enterprise Security 11-12-2019
0 0
0
0
emkaxon
Hello guys, We are trying to collect logs from our Active directory into Splunk enterprise, however we were getting ...
by emkaxon New Member in Splunk Enterprise Security 11-12-2019
0 0
0
0
stroud_bc
I am attempting to create a custom Risk Attribution rule based on Web Proxy traffic to newly-seen (not-seen-before-ye...
by stroud_bc Path Finder in Splunk Enterprise Security 11-11-2019
0 1
0
1
cchintha
All, Need help with combining logs from Load Balancer/SNAT and AD Domain Controller to get the combined results in a ...
by cchintha New Member in Splunk Enterprise Security 11-11-2019
0 1
0
1
N92
I have result in one field from the lookup and also result in second field(multivalue results) from lookup. Accessed...
by N92 Path Finder in Splunk Enterprise Security 11-11-2019
0 1
0
1
gbhw
Hi, I am building a vulnerability dashboard and got the following table: To make it easier to read I like to comb...
by gbhw New Member in Splunk Enterprise Security 11-11-2019
0 2
0
2
anishrai
Hi, Is it possible to integrate Firemon Server Control Panel with Splunk? Syslog can be enabled on Firemon SCP.
by anishrai New Member in Splunk Enterprise Security 11-11-2019
0 0
0
0
SplunkNewbie18
Hi, I've got 2 index logs to do a comparison with for emails. So in my mind is to use subsearch and join - but doesn...
by SplunkNewbie18 New Member in Splunk Enterprise Security 11-09-2019
0 5
0
5
danielbb
Looking at Splunk_TA_symantec-ep and I wonder where the documentation for the sourcetypes, which are CIM compliant, i...
by danielbb Motivator in Splunk Enterprise Security 11-08-2019
0 1
0
1
nando10
I've been working on a problem that has me stumped. I have a 4624 and 4633 event that I want to correspond with eac...
by nando10 Explorer in Splunk Enterprise Security 11-08-2019
1 11
1
11
tiaatim
Hi, I have the Cisco ASA TA installed and things look great on my Enterprise Security search head when I search for t...
by tiaatim Path Finder in Splunk Enterprise Security 11-08-2019
0 11
0
11
SplunkNewbie18
Hi, I'm trying to match email events which may consists of alphabets, numbers and special characters and do a count ...
by SplunkNewbie18 New Member in Splunk Enterprise Security 11-07-2019
0 2
0
2
richardphung
With Security Essentials, I get an error: [Indexer] Streamed search execute failed because: Error in 'lookup' comman...
by richardphung Communicator in Splunk Enterprise Security 11-07-2019
0 0
0
0
siddh01r
HI all, Anyone out there had any benefit from the free Threat intel List in Splunk ES? Its causing alot of noise, I...
by siddh01r New Member in Splunk Enterprise Security 11-06-2019
0 2
0
2
premforsplunk
Hi folks, I'm trying to install newly released Splunk ES 6.0, but it keeps on failing during the "post installation c...
by premforsplunk Explorer in Splunk Enterprise Security 11-06-2019
1 5
1
5
janispelss
I have been looking into upgrading our Splunk Enterprise deployment to version 7.1.1, which would also require upgrad...
by janispelss Path Finder in Splunk Enterprise Security 11-05-2019
3 1
3
1
garciajbg
PLEASE BE PATIENT I AM NEW TO THIS All, I am trying to use the results of a search (search 1) and create a new field...
by garciajbg Explorer in Splunk Enterprise Security 11-05-2019
1 12
1
12
williamsmew
I cant figure this out. I cant get my query to check a lookup to verify if the identified recipient from the phish l...
by williamsmew New Member in Splunk Enterprise Security 11-05-2019
0 4
0
4
Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Unlocking Data-In-Place Search Across Splunk and Snowflake  Enterprise data is increasingly distributed across ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...