Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
danielbb
With all the help from @solarboyz1, the correlation searches produce now notable events, which show up in the Inciden...
by danielbb Motivator in Splunk Enterprise Security 09-13-2019
0 3
0
3
danielbb
I try to assign an event to myself, but I get the following message - -- Unable to change 1 events: The search is n...
by danielbb Motivator in Splunk Enterprise Security 09-13-2019
0 2
0
2
danielbb
I go to Configure > Content > Use Case Library. It shows this nice page but I can't view all the use cases. Meaning...
by danielbb Motivator in Splunk Enterprise Security 09-12-2019
0 4
0
4
snigdhasaxena
This is a dependent dropdown. since the token in query,ac_domain has value, customer_name. index has fields aws_acc...
by snigdhasaxena Communicator in Splunk Enterprise Security 09-12-2019
0 0
0
0
danielbb
I'm looking at the Web datamodel and try to determine which fields are populated. I can do : | tstats dc(sourcetyp...
by danielbb Motivator in Splunk Enterprise Security 09-12-2019
0 5
0
5
mrockowitz_splu
0
2
gf13579
I have a significant number of Notables raised by the Substantial Increase in Port Activity correlation search. Pick...
by gf13579 Communicator in Splunk Enterprise Security 09-11-2019
0 10
0
10
satyaallaparthi
Hello, My schedule jobs are skipping all the time and getting following reasons: The maximum number of concurrent ...
by satyaallaparthi Communicator in Splunk Enterprise Security 09-11-2019
0 5
0
5
jamolson
Hello again everyone, Was wondering if anyone has been able to get Phantom Playbook Prompts to be able to nest respo...
by jamolson Path Finder in Splunk Enterprise Security 09-10-2019
0 1
0
1
mmoermans
Hi, In ES there is a bogonlist included with subnet masks for bogus ip ranges. How is this used standard in Splunk E...
by mmoermans Path Finder in Splunk Enterprise Security 09-10-2019
0 1
0
1
singhvishakha29
Hi All, I tried to install the app "G-Suite For Splunk" and was able to do both the authentications successfully. Wh...
by singhvishakha29 Engager in Splunk Enterprise Security 09-10-2019
0 0
0
0
bestSplunker
hi ,everyone! Recently my splunk always received the following error message.I suspect it is a problem for splunk E...
by bestSplunker Contributor in Splunk Enterprise Security 09-10-2019
1 5
1
5
andresito123
I have changed the identities.csv and prolonged the expiration of an identity. However, the alert keep getting trigge...
by andresito123 Communicator in Splunk Enterprise Security 09-10-2019
0 2
0
2
splunk2019vg
Hi Experts, My Splunk SIEM sandbox never opened . I have received an email which has link to open sandbox and from y...
by splunk2019vg New Member in Splunk Enterprise Security 09-09-2019
0 1
0
1
irsysintegratio
Hello, We have an AR Action, and it works fine with correlation search. But when we try to invoke it as adhoc action...
by irsysintegratio Path Finder in Splunk Enterprise Security 09-09-2019
0 13
0
13
reubenjoseph
We have created a large amount of custom Adaptive response actions that primarily consist of actions that fetch infor...
by reubenjoseph Explorer in Splunk Enterprise Security 09-09-2019
0 6
0
6
dillardo_2
From the Monitoring Console: Health Check: msg="A script exited abnormally with exit status: 4" input="./opt/splunk...
by dillardo_2 Path Finder in Splunk Enterprise Security 09-09-2019
0 3
0
3
rupeshn
index="A" sourcetype=B action=Yes | search NOT [ search index="A" sourcetype=B action="No" | fields User ] | stats co...
by rupeshn Explorer in Splunk Enterprise Security 09-09-2019
1 11
1
11
gcusello
Hi at all, I have the following architecture: 2 clustered Indexers,2 Search Heads,1 Master Node,1 Deployment Server....
by SplunkTrust SplunkTrust in Splunk Enterprise Security 09-09-2019
0 5
0
5
smote01
I wanted to take malicious IP's/URL's that the threat Intel feeds provides and compare them against logs/traffic we s...
by smote01 New Member in Splunk Enterprise Security 09-05-2019
0 0
0
0
shrutheen
I want to add a new Security Domain called "Email" in Enterprise Security (ES) App and later map it to notables. Righ...
by shrutheen Explorer in Splunk Enterprise Security 09-05-2019
1 1
1
1
santosh_scb
Hi Team, We are performing Splunk ES upgrade from 4.7.1 to 5.2.0. Post upgrade, I have few .xml, .json files that ne...
by santosh_scb Path Finder in Splunk Enterprise Security 09-04-2019
0 2
0
2
willadams
We have recently installed Enterprise Security and have enabled a few use cases. This was done with the guidance of ...
by willadams Contributor in Splunk Enterprise Security 09-04-2019
0 2
0
2
sylim_splunk
When creating a managed lookup and the destination app is chosen to be a custom app we made (that ES inherits), it cr...
by sylim_splunk Splunk Employee Splunk Employee in Splunk Enterprise Security 09-04-2019
1 1
1
1
LukeMurphey
I have a Correlation Search that didn't generate notable events in a couple where I think it should have. How can I d...
by LukeMurphey Champion in Splunk Enterprise Security 09-04-2019
1 4
1
4
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...
Top Solution Authors