Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
splunk_zen
Need some clarification regarding enabling "Accelerate until maximum time" according to the docs "When selected, r...
by splunk_zen Builder in Splunk Enterprise Security 06-03-2019
0 6
0
6
nb1030
We have the Bro add-on installed and everything is being parsed into the proper fields. The Bro DNS logs (sourcetype=...
by nb1030 New Member in Splunk Enterprise Security 06-02-2019
0 2
0
2
lxm30
I have two fields and if field1 is empty, I want to use the value in field2. (i.e. I never want to use field2 unless ...
by lxm30 New Member in Splunk Enterprise Security 05-31-2019
0 3
0
3
regriffith
I need to extract various fields if they exist. CN, C, S, O, OU, Here is a sample data of five different events. P...
by regriffith Path Finder in Splunk Enterprise Security 05-30-2019
0 8
0
8
jolinchew
I try to find PDF documentation for Cyber-security hunting guide, I try below documentation link: https://docs.splun...
by jolinchew New Member in Splunk Enterprise Security 05-28-2019
0 3
0
3
shravankumarkus
I want get contributing events for a particular notable event programatically. Is there anyway that we can get from ...
by shravankumarkus New Member in Splunk Enterprise Security 05-27-2019
0 4
0
4
hoandh
Hi all, When I config assets in SplunkES, I have a problem which concern field pci_domain. I have read the document...
by hoandh New Member in Splunk Enterprise Security 05-27-2019
0 7
0
7
rashid47010
I am seeing some interesting information from cisco Iogs. for example, user name, hostname name, mac address, locatio...
by rashid47010 Communicator in Splunk Enterprise Security 05-27-2019
0 2
0
2
singhvishakha29
Hi All, For the Cloudtrail logs, this is the last logs in splunkd logfile. 05-22-2019 08:15:02.624 +0000 INFO In...
by singhvishakha29 Engager in Splunk Enterprise Security 05-27-2019
0 0
0
0
simon_lavigne
Is it possible to import Splunk Enterprise Security and ESCU use cases into Splunk Security Essentials? I want to b...
by simon_lavigne Path Finder in Splunk Enterprise Security 05-26-2019
0 10
0
10
singhvishakha29
Hi All, I would like to know about the process to update the CIM. I am currently getting the following errors: Splu...
by singhvishakha29 Engager in Splunk Enterprise Security 05-24-2019
0 1
0
1
harishbenne2
I have 2 indexes that have 2 different parts of same data. One index contains http connection details and another con...
by harishbenne2 Explorer in Splunk Enterprise Security 05-23-2019
0 8
0
8
tjgamez
Hi all, I am new to Splunk and am still trying to figure out everything one step at a time. I have an issue where th...
by tjgamez New Member in Splunk Enterprise Security 05-23-2019
0 3
0
3
adam_dixon95
Hi, I'm looking at enabling the 'DNS Query Requests Resolved by Unauthorized DNS Servers' rule in Splunk ES - Unfort...
by adam_dixon95 Explorer in Splunk Enterprise Security 05-23-2019
0 1
0
1
TetchyTech
We have our Splunk - Resilient integration mostly working and wanted to add a script in Resilient to update the statu...
by TetchyTech New Member in Splunk Enterprise Security 05-22-2019
0 0
0
0
nnimbe1
Hi All, Can we translate our plain English queries to Search Processing Language i.e. SPL, does Splunk provide any f...
by nnimbe1 Path Finder in Splunk Enterprise Security 05-22-2019
0 2
0
2
SMWickman
I'm looking to add an input lookup to a tstats Datamodel correlation search within Splunk Enterprise Security to tune...
by SMWickman Explorer in Splunk Enterprise Security 05-21-2019
0 0
0
0
pcnitk
We are getting speacial characters in splunk raw message which is impacting downstream parsing. Can you suggest ways ...
by pcnitk New Member in Splunk Enterprise Security 05-20-2019
0 1
0
1
swright_rl
Hi, I'm trying to make a whitelist for encoded commands which IT Support use and I'm having a problem getting an inp...
by swright_rl Explorer in Splunk Enterprise Security 05-20-2019
0 2
0
2
Oracle
Hi Guys, Need help on this... Currently, we have ongoing integration of Splunk forwarder to Deployment Server the is...
by Oracle Explorer in Splunk Enterprise Security 05-19-2019
0 2
0
2
richardphung
We are using ES with a datamodel that has the base constraint: (`cim_Malware_indexes`) tag=malware tag=attack ...
by richardphung Communicator in Splunk Enterprise Security 05-18-2019
0 15
0
15
singhvishakha29
We need to decide on the best and easy option to collect all kinds of windows event logs
by singhvishakha29 Engager in Splunk Enterprise Security 05-16-2019
0 3
0
3
mtmichaelthomas
I have been playing around with creating dashboards and wanted to create one that can count how many tickets have bee...
by mtmichaelthomas New Member in Splunk Enterprise Security 05-16-2019
0 1
0
1
gpsvsoc
I'm trying to post a csv file that I've generated from a outputlookup to a url. For example http://splunk.test.test2...
by gpsvsoc Engager in Splunk Enterprise Security 05-16-2019
0 0
0
0
jarkkokinnunen
Hi, I tried to find out how to exclude tags from tstats search. My search is: | tstats summariesonly=true allow_old...
by jarkkokinnunen New Member in Splunk Enterprise Security 05-16-2019
0 0
0
0
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors