Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
Alspeedo
We are using Splunk es. We started porting list into the threat intel feeds. Our analyst wants to remove a single IP ...
by Alspeedo Engager in Splunk Enterprise Security 05-03-2019
1 1
1
1
saurabhsumangat
Since morning i am observing my notables are not getting created. I can see the Notable names in Security posture but...
by saurabhsumangat New Member in Splunk Enterprise Security 05-02-2019
0 8
0
8
Splunk_rocks
Hello Splunkers we have splunk managed cloud ES and i have enabled all correlation searches as per doc the way we do ...
by Splunk_rocks Path Finder in Splunk Enterprise Security 05-01-2019
0 1
0
1
dsmeerkat
I have URL's that contain email addresses that I would like to extract via rex into an email field: SAMPLE RAW: mac...
by dsmeerkat Explorer in Splunk Enterprise Security 05-01-2019
0 3
0
3
jwalzerpitt
We have ES up and running and I'm starting to review the various Security Domains and relevant dashboards/reports. F...
by jwalzerpitt Influencer in Splunk Enterprise Security 05-01-2019
0 2
0
2
cpaul8
Hello, The add-on for MS sysmon developed by Dave Herrald has been tested for Sysmon version 8.0 as per the link, bu...
by cpaul8 New Member in Splunk Enterprise Security 05-01-2019
0 1
0
1
rtsquared
We have connected Duo Security with Splunk in order to track certain aspects of our security performance. To make thi...
by rtsquared Explorer in Splunk Enterprise Security 04-30-2019
0 3
0
3
su_kumar
Hi , I am new and trying to write setup page through modular input where we need to communicate with server .for use...
by su_kumar New Member in Splunk Enterprise Security 04-30-2019
0 3
0
3
pingads11
Hi, Please let me know what is possible way to disable info page (en-US/info) without authentication as it showing d...
by pingads11 New Member in Splunk Enterprise Security 04-30-2019
0 0
0
0
chrispounds
Hi all, So i have added the edit_timeline role to a user and they can create an investigation, but after you click ...
by chrispounds Explorer in Splunk Enterprise Security 04-30-2019
0 5
0
5
bbraun
Hello, We have multiple international locations (Japan, Italy, Spain ect...) and are looking to identify events that...
by bbraun New Member in Splunk Enterprise Security 04-29-2019
0 3
0
3
david_monaghan
I recently upgraded the Cisco WSA TA and now all WSA logs are being tagged as Malware and Attack traffic. It seems t...
by david_monaghan Engager in Splunk Enterprise Security 04-26-2019
0 0
0
0
Rocky31
I am just confused to install Splunk app (truStar) via terminal, please don't tell me to download and upload via Splu...
by Rocky31 Path Finder in Splunk Enterprise Security 04-26-2019
0 7
0
7
saurabhsumangat
i written a query and need to change the output name of one the table column ....| chart count over sourceIP by Stat...
by saurabhsumangat New Member in Splunk Enterprise Security 04-26-2019
0 1
0
1
saurabhsumangat
till few afters before all my notables were working properly. I made changes in XML file of default.xml on navigation...
by saurabhsumangat New Member in Splunk Enterprise Security 04-25-2019
0 2
0
2
bcyates
Is there a way to automagically add a unique ID number to each investigation that is opened?
by bcyates Communicator in Splunk Enterprise Security 04-25-2019
0 2
0
2
wendtb
I am trying to add a view to Enterprise Security by going to Configure > General > Navigation. Here I am able to crea...
by wendtb Path Finder in Splunk Enterprise Security 04-25-2019
0 1
0
1
hrithiktej
I have these events on Splunk ES security posture dashboard and need help in understand how the detection for this on...
by hrithiktej Communicator in Splunk Enterprise Security 04-25-2019
0 3
0
3
metalgear138
Just wanted to put this out there to the universe... Has anyone set up a custom search/alert to track when the Window...
by metalgear138 Engager in Splunk Enterprise Security 04-25-2019
0 5
0
5
saurabhsumangat
I have recently modified my navigation menu XML through splunk user interface. Now when i refresh the splunk instanc...
by saurabhsumangat New Member in Splunk Enterprise Security 04-25-2019
0 0
0
0
richardphung
We are having an issue with our Splunk ES instance where notables that have dest = unknown, all show up in our ESS In...
by richardphung Communicator in Splunk Enterprise Security 04-25-2019
0 2
0
2
rashid47010
how can I add existing key indicator to my new dashboard. I want to add malware key indicator to my custom dashboard...
by rashid47010 Communicator in Splunk Enterprise Security 04-25-2019
0 1
0
1
rohitvjoshi
Hi All, We are using Splunk Enterprise, During server cleaning, We found out that Splunk Enterprise security is als...
by rohitvjoshi Path Finder in Splunk Enterprise Security 04-24-2019
0 1
0
1
yosoypako
Hello I want to index the events in the firewalls log based in the alert level and the virtual domain in witch they h...
by yosoypako Path Finder in Splunk Enterprise Security 04-24-2019
0 9
0
9
lakshman239
Hello @douglashurd - Could you pls review default/props.conf as its reusing same name [FIELDALIAS-eStreamer_category...
by lakshman239 Influencer in Splunk Enterprise Security 04-24-2019
0 0
0
0
Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...