Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
brian1_tate
Myron, Thank you for taking the time to put into this TA. It's appears to be really useful with the way that Meraki ...
by brian1_tate Path Finder in Splunk Enterprise Security 05-06-2019
0 4
0
4
arorayo
Team, I am trying to setup a use case about To detect if Local admin account has been used to logon to a system , w...
by arorayo New Member in Splunk Enterprise Security 05-06-2019
0 2
0
2
adam_dixon95
Hi, I have the following search in an ES dashboard panel to order incidents throughout the month by severity in a ba...
by adam_dixon95 Explorer in Splunk Enterprise Security 05-06-2019
1 1
1
1
TheSplunkDude
I’m trying to populate my users with the following query. One of the issues I have is certain users don’t have the ma...
by TheSplunkDude Explorer in Splunk Enterprise Security 05-06-2019
0 0
0
0
jwalzerpitt
I created an alias for the X_MS_Forwarded_Client_IP (ADFS events) to equal to src. The X_MS_Forwarded_Client_IP is a ...
by jwalzerpitt Influencer in Splunk Enterprise Security 05-06-2019
0 2
0
2
Crashfry
I'll start with the goal of what I am trying to accomplish first. I'd like to be able to detect any source sending da...
by Crashfry Path Finder in Splunk Enterprise Security 05-06-2019
0 2
0
2
benthehen100
Hello, I'm trying to create a dashboard for our email logs, that allows a user to input fields like sender, recipien...
by benthehen100 Engager in Splunk Enterprise Security 05-03-2019
0 0
0
0
Alspeedo
We are using Splunk es. We started porting list into the threat intel feeds. Our analyst wants to remove a single IP ...
by Alspeedo Engager in Splunk Enterprise Security 05-03-2019
1 1
1
1
saurabhsumangat
Since morning i am observing my notables are not getting created. I can see the Notable names in Security posture but...
by saurabhsumangat New Member in Splunk Enterprise Security 05-02-2019
0 8
0
8
Splunk_rocks
Hello Splunkers we have splunk managed cloud ES and i have enabled all correlation searches as per doc the way we do ...
by Splunk_rocks Path Finder in Splunk Enterprise Security 05-01-2019
0 1
0
1
dsmeerkat
I have URL's that contain email addresses that I would like to extract via rex into an email field: SAMPLE RAW: mac...
by dsmeerkat Explorer in Splunk Enterprise Security 05-01-2019
0 3
0
3
jwalzerpitt
We have ES up and running and I'm starting to review the various Security Domains and relevant dashboards/reports. F...
by jwalzerpitt Influencer in Splunk Enterprise Security 05-01-2019
0 2
0
2
cpaul8
Hello, The add-on for MS sysmon developed by Dave Herrald has been tested for Sysmon version 8.0 as per the link, bu...
by cpaul8 New Member in Splunk Enterprise Security 05-01-2019
0 1
0
1
rtsquared
We have connected Duo Security with Splunk in order to track certain aspects of our security performance. To make thi...
by rtsquared Explorer in Splunk Enterprise Security 04-30-2019
0 3
0
3
su_kumar
Hi , I am new and trying to write setup page through modular input where we need to communicate with server .for use...
by su_kumar New Member in Splunk Enterprise Security 04-30-2019
0 3
0
3
pingads11
Hi, Please let me know what is possible way to disable info page (en-US/info) without authentication as it showing d...
by pingads11 New Member in Splunk Enterprise Security 04-30-2019
0 0
0
0
chrispounds
Hi all, So i have added the edit_timeline role to a user and they can create an investigation, but after you click ...
by chrispounds Explorer in Splunk Enterprise Security 04-30-2019
0 5
0
5
bbraun
Hello, We have multiple international locations (Japan, Italy, Spain ect...) and are looking to identify events that...
by bbraun New Member in Splunk Enterprise Security 04-29-2019
0 3
0
3
david_monaghan
I recently upgraded the Cisco WSA TA and now all WSA logs are being tagged as Malware and Attack traffic. It seems t...
by david_monaghan Engager in Splunk Enterprise Security 04-26-2019
0 0
0
0
Rocky31
I am just confused to install Splunk app (truStar) via terminal, please don't tell me to download and upload via Splu...
by Rocky31 Path Finder in Splunk Enterprise Security 04-26-2019
0 7
0
7
saurabhsumangat
i written a query and need to change the output name of one the table column ....| chart count over sourceIP by Stat...
by saurabhsumangat New Member in Splunk Enterprise Security 04-26-2019
0 1
0
1
saurabhsumangat
till few afters before all my notables were working properly. I made changes in XML file of default.xml on navigation...
by saurabhsumangat New Member in Splunk Enterprise Security 04-25-2019
0 2
0
2
bcyates
Is there a way to automagically add a unique ID number to each investigation that is opened?
by bcyates Communicator in Splunk Enterprise Security 04-25-2019
0 2
0
2
wendtb
I am trying to add a view to Enterprise Security by going to Configure > General > Navigation. Here I am able to crea...
by wendtb Path Finder in Splunk Enterprise Security 04-25-2019
0 1
0
1
hrithiktej
I have these events on Splunk ES security posture dashboard and need help in understand how the detection for this on...
by hrithiktej Communicator in Splunk Enterprise Security 04-25-2019
0 3
0
3
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...
Top Solution Authors