Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
KingUs80
I'm trying to resolve an issue where Splunk sends email reports, but the information exported as an attachment uses a...
by KingUs80 Loves-to-Learn Lots in Splunk Enterprise Security 09-30-2024
0 5
0
5
Joesplunk
How to fix"Could not load lookup=LOOKUP-autolookup_prices"
by Joesplunk New Member in Splunk Enterprise Security 09-26-2024
0 1
0
1
jfournet
I am using the following html for my alert action data entry screen.  The tenant mulit-select does not show up in the...
by jfournet New Member in Splunk Enterprise Security 09-23-2024
0 0
0
0
echojacques
In Enterprise Security, you can configure Notable Event Suppressions. When adding/editing a suppression, which file ...
by echojacques Builder in Splunk Enterprise Security 09-23-2024
0 7
0
7
beano501
We are trying to ingest a STIX file into the Threat Intelligence Management, the STIX parses, but does not find anyth...
by beano501 Explorer in Splunk Enterprise Security 09-22-2024
0 1
0
1
rbenbenish
When running a search on the Incident Review dashboard where the search term is the <event_id> value or event_id="<ev...
by rbenbenish New Member in Splunk Enterprise Security 09-19-2024
0 0
0
0
user487596
Hi everyone!Is it possible to pass a parameter from search to the next "action|url" step? Like in description: $resul...
by user487596 Explorer in Splunk Enterprise Security 09-17-2024
0 0
0
0
hazem
We have a cluster with two search heads and two indexers. We need to install the Enterprise Security app on the searc...
by hazem Path Finder in Splunk Enterprise Security 09-17-2024
0 2
0
2
aluvian
Hi,We were using Splunk Enterprise (8.2.5) and ESS (7.2.0) on Debian 12. Everything was working fine until I upgraded...
by aluvian Loves-to-Learn Everything in Splunk Enterprise Security 09-16-2024
0 4
0
4
vikas_gopal
Hello Splunk ES experts ,  I want to make a query which will produce MTTD (something like by analyzing the time diffe...
by vikas_gopal Builder in Splunk Enterprise Security 09-14-2024
0 4
0
4
kareem
Salam guysI wrote the Correlation Search Query and added the Adaptive Response Actions (notable, risk analysis and se...
by kareem Explorer in Splunk Enterprise Security 09-14-2024
0 0
0
0
Splunkers2
Hi all,I'm having issues comparing user field in Palo Alto traffic logs vs last user reported by Crowdstrike/Windows ...
by Splunkers2 Observer in Splunk Enterprise Security 09-14-2024
0 3
0
3
VijaySrrie
Hi All,I need to download and install below app via command linehttps://splunkbase.splunk.com/app/263Please help me w...
by VijaySrrie Builder in Splunk Enterprise Security 09-13-2024
0 1
0
1
tuts
 Hello Splunk Community,I have .evtx files from several devices, and I would like to analyze them using Splunk Univer...
by tuts Path Finder in Splunk Enterprise Security 09-11-2024
0 3
0
3
wlight600
Hi! I'm creating custom alert action. I can use my alert action in save alert and Correlation search. But I meet ...
by wlight600 Engager in Splunk Enterprise Security 09-10-2024
0 14
0
14
tdth
Hi all,Has anyone had experience matching Linux audit logs to CIM before?I installed the Add-on for Unix and Linux, b...
by tdth Explorer in Splunk Enterprise Security 09-06-2024
0 3
0
3
zksvc
I Have 60 Correlation Search in Content Management Some of my Correlation Search doesn't trigger to Incident Review b...
by zksvc Contributor in Splunk Enterprise Security 09-05-2024
0 0
0
0
tuts
Hello, I am currently working in a SOC, and I want to test rules in Splunk ES using the BOTSv2 dataset. How can I con...
by tuts Path Finder in Splunk Enterprise Security 09-03-2024
0 1
0
1
corti77
Hi,I am testing the Security Essentials App 3.8.0 in Splunk 9.0.8, and I found the same issue while trying to activat...
by corti77 Contributor in Splunk Enterprise Security 09-02-2024
0 4
0
4
tadecleid
I found a similar post that did not quite fit the bill of what I am trying to do.I want to be able to create a link g...
by tadecleid New Member in Splunk Enterprise Security 09-02-2024
0 0
0
0
splunk_user9968
I would like to create a search with data models where my event id is 39. However, there is no datamodel that fulfill...
by splunk_user9968 New Member in Splunk Enterprise Security 08-27-2024
0 1
0
1
f_666dhn
I have lookup file bad_domain.csvbaddomain.combaddomain2.combaddomain3.com Then i want to search from proxy log, who ...
by f_666dhn Explorer in Splunk Enterprise Security 08-13-2024
0 1
0
1
japo86
I request that there be the ability to create groups of users in enterprise security so that when you need to add the...
by japo86 New Member in Splunk Enterprise Security 08-02-2024
0 1
0
1
vtalanki
Hi All, I want to enable SSL for Splunk management port(8089) for securing inter-splunk communications. I have below ...
by vtalanki Path Finder in Splunk Enterprise Security 08-01-2024
0 4
0
4
ThuLe
Hello,I'm trying to add new/existing key indicator searches to my dashboard in ES, but the edit toolbar does not have...
by ThuLe Explorer in Splunk Enterprise Security 07-30-2024
0 3
0
3
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...
Top Solution Authors