Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
danielbb
The team here is not satisfied with the capabilities, workflow of the Incident Review section of ES. Is there a nice ...
by danielbb Motivator in Splunk Enterprise Security 10-15-2019
0 1
0
1
vikram1583
I created few correlation searches notable events in Enterprise security and in Incident Review - Table Attributes I...
by vikram1583 Explorer in Splunk Enterprise Security 10-15-2019
0 1
0
1
samadmemon
Hi All, Request you to post the query for retrieving messages displayed on the top of the UI so that a Dashboard/rep...
by samadmemon Explorer in Splunk Enterprise Security 10-15-2019
0 1
0
1
danielbb
We are wondering how to enable the automatic updates by the ESCU. We have it working fine but it doesn't seem to fetc...
by danielbb Motivator in Splunk Enterprise Security 10-15-2019
0 5
0
5
danielbb
src_user shows only 5 or so of percent_coverage in the cim_validator for our Windows data. Fields for Authentication...
by danielbb Motivator in Splunk Enterprise Security 10-15-2019
0 4
0
4
samadmemon
Hi All, We have an environment where the owner of all the Dashboards/Alerts is user 'nobody'. Are there any disadvan...
by samadmemon Explorer in Splunk Enterprise Security 10-15-2019
0 0
0
0
splunkbeginner
After upgrade to Splunk Enterprise Security v 5.3.1, fail on startup with the following error: [root@splunk02 bin]# ...
by splunkbeginner Engager in Splunk Enterprise Security 10-15-2019
0 1
0
1
abwe
I've recently indexed kaspersky security center 10 data in splunk, but malware center in enterprise security showed n...
by abwe Loves-to-Learn Lots in Splunk Enterprise Security 10-14-2019
0 3
0
3
vikram1583
index=email | transaction mid icid | stats count(recipient) as receipent_count by sender | where receipent_count>1...
by vikram1583 Explorer in Splunk Enterprise Security 10-13-2019
0 2
0
2
Arpmjdr
Hi Fellows, I need to change the title of existing correlation search which I am not able to do as the options are g...
by Arpmjdr Explorer in Splunk Enterprise Security 10-13-2019
1 3
1
3
aalaa
Hello , We have a Splunk ES 5.1.0 application installed on Splunk Entreprise version 7.2.0. We need to collect the...
by aalaa Path Finder in Splunk Enterprise Security 10-11-2019
0 0
0
0
danman81
Does the MLTK support multi-output classification, i.e., more than 1 predicted field? Thank you.
by danman81 Engager in Splunk Enterprise Security 10-10-2019
0 4
0
4
utk123
I have 2 different searches to create 2 hosts list, and I want below from splunk search: 1. Find all hosts from 1st s...
by utk123 Path Finder in Splunk Enterprise Security 10-09-2019
0 2
0
2
andykrnac
Dear all, I have downloaded SPL tared image at https://splunkbase.splunk.com/app/4516/ and I want to deploy it Linux...
by andykrnac New Member in Splunk Enterprise Security 10-09-2019
0 3
0
3
ss656204
We have received notice that our splunk heavy forwarder is vulnerable to CVE-2016-2183 , CVE-2013-2566,CVE-2015-2808....
by ss656204 New Member in Splunk Enterprise Security 10-09-2019
0 0
0
0
jwalzerpitt
We recently started to ingest Microsoft's Azure sign-in events and one thing I've noticed are some values from the cl...
by jwalzerpitt Influencer in Splunk Enterprise Security 10-09-2019
0 0
0
0
cyber4good
Hello Everyone I am curious to learn with BOTS 2.0 but need some help. I have downloaded BOTS 2.0 but unable to fin...
by cyber4good Engager in Splunk Enterprise Security 10-09-2019
1 2
1
2
pradeep577
Hi, I need to be alerted when a rogue/unknown device is plugged into network. Any help will be appreciated.
by pradeep577 Path Finder in Splunk Enterprise Security 10-08-2019
0 2
0
2
barcher83
The ES correlation search 'DNS Query Requests Resolved by Unauthorized DNS Servers' determines if the traffic is to f...
by barcher83 Explorer in Splunk Enterprise Security 10-07-2019
0 2
0
2
hamzeh_khosravi
Hi Dear Friends, I installed "Splunk Add-on for Unix and Linux" and now i have a question What parts of the Enterpris...
by hamzeh_khosravi New Member in Splunk Enterprise Security 10-07-2019
0 0
0
0
bbiswabhusan
Hello experts, I am trying to integration salesforce cloud modules into splunk for security monitoring. Does anyne ha...
by bbiswabhusan Explorer in Splunk Enterprise Security 10-07-2019
0 1
0
1
shubham1234
Hi Everyone, I have a splunk search: Search: sourcetype = onelogin:event index = onelogin earliest=-12d AND event_ty...
by shubham1234 New Member in Splunk Enterprise Security 10-05-2019
0 3
0
3
RK_sp1unk
Splunk Enterprise security search head is not pulling logs from firewall, waf,proxy logs, MFA, sandbox, ...network r...
by RK_sp1unk New Member in Splunk Enterprise Security 10-02-2019
0 0
0
0
rossikwan
Hi, Configured the proxy for retrieving threat intelligence in Enterprise Security and its succesfully retrieved th...
by rossikwan Path Finder in Splunk Enterprise Security 10-02-2019
0 1
0
1
bowesmana
I setup a saved search and it is failing to run. It is throwing an error in the gui Error in 'sendalert' command: Al...
by SplunkTrust SplunkTrust in Splunk Enterprise Security 10-01-2019
0 1
0
1
Get Updates on the Splunk Community!

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors