Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
kaushalp95
Hello, I would like to upload a custom app to Splunk Enterprise Security Sandbox Cloud environment and/or is possible...
by kaushalp95 New Member in Splunk Enterprise Security 05-07-2019
0 0
0
0
brian1_tate
Myron, Thank you for taking the time to put into this TA. It's appears to be really useful with the way that Meraki ...
by brian1_tate Path Finder in Splunk Enterprise Security 05-06-2019
0 4
0
4
arorayo
Team, I am trying to setup a use case about To detect if Local admin account has been used to logon to a system , w...
by arorayo New Member in Splunk Enterprise Security 05-06-2019
0 2
0
2
adam_dixon95
Hi, I have the following search in an ES dashboard panel to order incidents throughout the month by severity in a ba...
by adam_dixon95 Explorer in Splunk Enterprise Security 05-06-2019
1 1
1
1
TheSplunkDude
I’m trying to populate my users with the following query. One of the issues I have is certain users don’t have the ma...
by TheSplunkDude Explorer in Splunk Enterprise Security 05-06-2019
0 0
0
0
jwalzerpitt
I created an alias for the X_MS_Forwarded_Client_IP (ADFS events) to equal to src. The X_MS_Forwarded_Client_IP is a ...
by jwalzerpitt Influencer in Splunk Enterprise Security 05-06-2019
0 2
0
2
Crashfry
I'll start with the goal of what I am trying to accomplish first. I'd like to be able to detect any source sending da...
by Crashfry Path Finder in Splunk Enterprise Security 05-06-2019
0 2
0
2
benthehen100
Hello, I'm trying to create a dashboard for our email logs, that allows a user to input fields like sender, recipien...
by benthehen100 Engager in Splunk Enterprise Security 05-03-2019
0 0
0
0
Alspeedo
We are using Splunk es. We started porting list into the threat intel feeds. Our analyst wants to remove a single IP ...
by Alspeedo Engager in Splunk Enterprise Security 05-03-2019
1 1
1
1
saurabhsumangat
Since morning i am observing my notables are not getting created. I can see the Notable names in Security posture but...
by saurabhsumangat New Member in Splunk Enterprise Security 05-02-2019
0 8
0
8
Splunk_rocks
Hello Splunkers we have splunk managed cloud ES and i have enabled all correlation searches as per doc the way we do ...
by Splunk_rocks Path Finder in Splunk Enterprise Security 05-01-2019
0 1
0
1
dsmeerkat
I have URL's that contain email addresses that I would like to extract via rex into an email field: SAMPLE RAW: mac...
by dsmeerkat Explorer in Splunk Enterprise Security 05-01-2019
0 3
0
3
jwalzerpitt
We have ES up and running and I'm starting to review the various Security Domains and relevant dashboards/reports. F...
by jwalzerpitt Influencer in Splunk Enterprise Security 05-01-2019
0 2
0
2
cpaul8
Hello, The add-on for MS sysmon developed by Dave Herrald has been tested for Sysmon version 8.0 as per the link, bu...
by cpaul8 New Member in Splunk Enterprise Security 05-01-2019
0 1
0
1
rtsquared
We have connected Duo Security with Splunk in order to track certain aspects of our security performance. To make thi...
by rtsquared Explorer in Splunk Enterprise Security 04-30-2019
0 3
0
3
su_kumar
Hi , I am new and trying to write setup page through modular input where we need to communicate with server .for use...
by su_kumar New Member in Splunk Enterprise Security 04-30-2019
0 3
0
3
pingads11
Hi, Please let me know what is possible way to disable info page (en-US/info) without authentication as it showing d...
by pingads11 New Member in Splunk Enterprise Security 04-30-2019
0 0
0
0
chrispounds
Hi all, So i have added the edit_timeline role to a user and they can create an investigation, but after you click ...
by chrispounds Explorer in Splunk Enterprise Security 04-30-2019
0 5
0
5
bbraun
Hello, We have multiple international locations (Japan, Italy, Spain ect...) and are looking to identify events that...
by bbraun New Member in Splunk Enterprise Security 04-29-2019
0 3
0
3
david_monaghan
I recently upgraded the Cisco WSA TA and now all WSA logs are being tagged as Malware and Attack traffic. It seems t...
by david_monaghan Engager in Splunk Enterprise Security 04-26-2019
0 0
0
0
Rocky31
I am just confused to install Splunk app (truStar) via terminal, please don't tell me to download and upload via Splu...
by Rocky31 Path Finder in Splunk Enterprise Security 04-26-2019
0 7
0
7
saurabhsumangat
i written a query and need to change the output name of one the table column ....| chart count over sourceIP by Stat...
by saurabhsumangat New Member in Splunk Enterprise Security 04-26-2019
0 1
0
1
saurabhsumangat
till few afters before all my notables were working properly. I made changes in XML file of default.xml on navigation...
by saurabhsumangat New Member in Splunk Enterprise Security 04-25-2019
0 2
0
2
bcyates
Is there a way to automagically add a unique ID number to each investigation that is opened?
by bcyates Communicator in Splunk Enterprise Security 04-25-2019
0 2
0
2
wendtb
I am trying to add a view to Enterprise Security by going to Configure > General > Navigation. Here I am able to crea...
by wendtb Path Finder in Splunk Enterprise Security 04-25-2019
0 1
0
1
Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...