| Team, I am trying to setup a use case about To detect if Local admin account has been used to logon to a system , w... by arorayo New Member in Splunk Enterprise Security 05-06-2019 0 2 | 0 | 2 | ||
| Hi, I have the following search in an ES dashboard panel to order incidents throughout the month by severity in a ba... by adam_dixon95 Explorer in Splunk Enterprise Security 05-06-2019 1 1 | 1 | 1 | ||
| I’m trying to populate my users with the following query. One of the issues I have is certain users don’t have the ma... by TheSplunkDude Explorer in Splunk Enterprise Security 05-06-2019 0 0 | 0 | 0 | ||
| I created an alias for the X_MS_Forwarded_Client_IP (ADFS events) to equal to src. The X_MS_Forwarded_Client_IP is a ... by jwalzerpitt Influencer in Splunk Enterprise Security 05-06-2019 0 2 | 0 | 2 | ||
| I'll start with the goal of what I am trying to accomplish first. I'd like to be able to detect any source sending da... by Crashfry Path Finder in Splunk Enterprise Security 05-06-2019 0 2 | 0 | 2 | ||
| Hello, I'm trying to create a dashboard for our email logs, that allows a user to input fields like sender, recipien... by benthehen100 Engager in Splunk Enterprise Security 05-03-2019 0 0 | 0 | 0 | ||
| We are using Splunk es. We started porting list into the threat intel feeds. Our analyst wants to remove a single IP ... by Alspeedo Engager in Splunk Enterprise Security 05-03-2019 1 1 | 1 | 1 | ||
| Since morning i am observing my notables are not getting created. I can see the Notable names in Security posture but... by saurabhsumangat New Member in Splunk Enterprise Security 05-02-2019 0 8 | 0 | 8 | ||
| Hello Splunkers we have splunk managed cloud ES and i have enabled all correlation searches as per doc the way we do ... by Splunk_rocks Path Finder in Splunk Enterprise Security 05-01-2019 0 1 | 0 | 1 | ||
| I have URL's that contain email addresses that I would like to extract via rex into an email field: SAMPLE RAW: mac... by dsmeerkat Explorer in Splunk Enterprise Security 05-01-2019 0 3 | 0 | 3 | ||
| We have ES up and running and I'm starting to review the various Security Domains and relevant dashboards/reports. F... by jwalzerpitt Influencer in Splunk Enterprise Security 05-01-2019 0 2 | 0 | 2 | ||
| Hello, The add-on for MS sysmon developed by Dave Herrald has been tested for Sysmon version 8.0 as per the link, bu... by cpaul8 New Member in Splunk Enterprise Security 05-01-2019 0 1 | 0 | 1 | ||
| We have connected Duo Security with Splunk in order to track certain aspects of our security performance. To make thi... by rtsquared Explorer in Splunk Enterprise Security 04-30-2019 0 3 | 0 | 3 | ||
| Hi , I am new and trying to write setup page through modular input where we need to communicate with server .for use... by su_kumar New Member in Splunk Enterprise Security 04-30-2019 0 3 | 0 | 3 | ||
| Hi, Please let me know what is possible way to disable info page (en-US/info) without authentication as it showing d... by pingads11 New Member in Splunk Enterprise Security 04-30-2019 0 0 | 0 | 0 | ||
| Hi all, So i have added the edit_timeline role to a user and they can create an investigation, but after you click ... by chrispounds Explorer in Splunk Enterprise Security 04-30-2019 0 5 | 0 | 5 | ||
| Hello, We have multiple international locations (Japan, Italy, Spain ect...) and are looking to identify events that... by bbraun New Member in Splunk Enterprise Security 04-29-2019 0 3 | 0 | 3 | ||
| I recently upgraded the Cisco WSA TA and now all WSA logs are being tagged as Malware and Attack traffic. It seems t... by david_monaghan Engager in Splunk Enterprise Security 04-26-2019 0 0 | 0 | 0 | ||
| I am just confused to install Splunk app (truStar) via terminal, please don't tell me to download and upload via Splu... by Rocky31 Path Finder in Splunk Enterprise Security 04-26-2019 0 7 | 0 | 7 | ||
| i written a query and need to change the output name of one the table column ....| chart count over sourceIP by Stat... by saurabhsumangat New Member in Splunk Enterprise Security 04-26-2019 0 1 | 0 | 1 | ||
| till few afters before all my notables were working properly. I made changes in XML file of default.xml on navigation... by saurabhsumangat New Member in Splunk Enterprise Security 04-25-2019 0 2 | 0 | 2 | ||
| Is there a way to automagically add a unique ID number to each investigation that is opened? by bcyates Communicator in Splunk Enterprise Security 04-25-2019 0 2 | 0 | 2 | ||
| I am trying to add a view to Enterprise Security by going to Configure > General > Navigation. Here I am able to crea... by wendtb Path Finder in Splunk Enterprise Security 04-25-2019 0 1 | 0 | 1 | ||
| I have these events on Splunk ES security posture dashboard and need help in understand how the detection for this on... by hrithiktej Communicator in Splunk Enterprise Security 04-25-2019 0 3 | 0 | 3 | ||
| Just wanted to put this out there to the universe... Has anyone set up a custom search/alert to track when the Window... by metalgear138 Engager in Splunk Enterprise Security 04-25-2019 0 5 | 0 | 5 |