Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
arorayo
Team, I am trying to setup a use case about To detect if Local admin account has been used to logon to a system , w...
by arorayo New Member in Splunk Enterprise Security 05-06-2019
0 2
0
2
adam_dixon95
Hi, I have the following search in an ES dashboard panel to order incidents throughout the month by severity in a ba...
by adam_dixon95 Explorer in Splunk Enterprise Security 05-06-2019
1 1
1
1
TheSplunkDude
I’m trying to populate my users with the following query. One of the issues I have is certain users don’t have the ma...
by TheSplunkDude Explorer in Splunk Enterprise Security 05-06-2019
0 0
0
0
jwalzerpitt
I created an alias for the X_MS_Forwarded_Client_IP (ADFS events) to equal to src. The X_MS_Forwarded_Client_IP is a ...
by jwalzerpitt Influencer in Splunk Enterprise Security 05-06-2019
0 2
0
2
Crashfry
I'll start with the goal of what I am trying to accomplish first. I'd like to be able to detect any source sending da...
by Crashfry Path Finder in Splunk Enterprise Security 05-06-2019
0 2
0
2
benthehen100
Hello, I'm trying to create a dashboard for our email logs, that allows a user to input fields like sender, recipien...
by benthehen100 Engager in Splunk Enterprise Security 05-03-2019
0 0
0
0
Alspeedo
We are using Splunk es. We started porting list into the threat intel feeds. Our analyst wants to remove a single IP ...
by Alspeedo Engager in Splunk Enterprise Security 05-03-2019
1 1
1
1
saurabhsumangat
Since morning i am observing my notables are not getting created. I can see the Notable names in Security posture but...
by saurabhsumangat New Member in Splunk Enterprise Security 05-02-2019
0 8
0
8
Splunk_rocks
Hello Splunkers we have splunk managed cloud ES and i have enabled all correlation searches as per doc the way we do ...
by Splunk_rocks Path Finder in Splunk Enterprise Security 05-01-2019
0 1
0
1
dsmeerkat
I have URL's that contain email addresses that I would like to extract via rex into an email field: SAMPLE RAW: mac...
by dsmeerkat Explorer in Splunk Enterprise Security 05-01-2019
0 3
0
3
jwalzerpitt
We have ES up and running and I'm starting to review the various Security Domains and relevant dashboards/reports. F...
by jwalzerpitt Influencer in Splunk Enterprise Security 05-01-2019
0 2
0
2
cpaul8
Hello, The add-on for MS sysmon developed by Dave Herrald has been tested for Sysmon version 8.0 as per the link, bu...
by cpaul8 New Member in Splunk Enterprise Security 05-01-2019
0 1
0
1
rtsquared
We have connected Duo Security with Splunk in order to track certain aspects of our security performance. To make thi...
by rtsquared Explorer in Splunk Enterprise Security 04-30-2019
0 3
0
3
su_kumar
Hi , I am new and trying to write setup page through modular input where we need to communicate with server .for use...
by su_kumar New Member in Splunk Enterprise Security 04-30-2019
0 3
0
3
pingads11
Hi, Please let me know what is possible way to disable info page (en-US/info) without authentication as it showing d...
by pingads11 New Member in Splunk Enterprise Security 04-30-2019
0 0
0
0
chrispounds
Hi all, So i have added the edit_timeline role to a user and they can create an investigation, but after you click ...
by chrispounds Explorer in Splunk Enterprise Security 04-30-2019
0 5
0
5
bbraun
Hello, We have multiple international locations (Japan, Italy, Spain ect...) and are looking to identify events that...
by bbraun New Member in Splunk Enterprise Security 04-29-2019
0 3
0
3
david_monaghan
I recently upgraded the Cisco WSA TA and now all WSA logs are being tagged as Malware and Attack traffic. It seems t...
by david_monaghan Engager in Splunk Enterprise Security 04-26-2019
0 0
0
0
Rocky31
I am just confused to install Splunk app (truStar) via terminal, please don't tell me to download and upload via Splu...
by Rocky31 Path Finder in Splunk Enterprise Security 04-26-2019
0 7
0
7
saurabhsumangat
i written a query and need to change the output name of one the table column ....| chart count over sourceIP by Stat...
by saurabhsumangat New Member in Splunk Enterprise Security 04-26-2019
0 1
0
1
saurabhsumangat
till few afters before all my notables were working properly. I made changes in XML file of default.xml on navigation...
by saurabhsumangat New Member in Splunk Enterprise Security 04-25-2019
0 2
0
2
bcyates
Is there a way to automagically add a unique ID number to each investigation that is opened?
by bcyates Communicator in Splunk Enterprise Security 04-25-2019
0 2
0
2
wendtb
I am trying to add a view to Enterprise Security by going to Configure > General > Navigation. Here I am able to crea...
by wendtb Path Finder in Splunk Enterprise Security 04-25-2019
0 1
0
1
hrithiktej
I have these events on Splunk ES security posture dashboard and need help in understand how the detection for this on...
by hrithiktej Communicator in Splunk Enterprise Security 04-25-2019
0 3
0
3
metalgear138
Just wanted to put this out there to the universe... Has anyone set up a custom search/alert to track when the Window...
by metalgear138 Engager in Splunk Enterprise Security 04-25-2019
0 5
0
5
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...
Top Solution Authors