Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
aothman
When I integrate with nessus I get [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed" I did the below but t...
by aothman New Member in Splunk Enterprise Security 04-12-2019
0 0
0
0
pranavna
I want to create an index which will have sensitive data and want it to be accessible by only admin team and security...
by pranavna Explorer in Splunk Enterprise Security 04-12-2019
0 4
0
4
rwells2950
I cannot save correlation searches through Splunk Enterprise Security in the context of any custom app. After going t...
by rwells2950 Engager in Splunk Enterprise Security 04-11-2019
0 5
0
5
nb1030
In the logs for "New Anti Virus", the logs contain a "dst=" and "src=" field. For some logs, it is placing the "dst="...
by nb1030 New Member in Splunk Enterprise Security 04-10-2019
0 3
0
3
lakshman239
** This is not a question, but adding this info for awareness for people using PA and CIM ** The default/tags.conf f...
by lakshman239 Influencer in Splunk Enterprise Security 04-10-2019
0 1
0
1
rashid47010
Threat activity detected correlation rule is too noisy because of IP_intel feeds. How can we exclude them.
by rashid47010 Communicator in Splunk Enterprise Security 04-10-2019
0 0
0
0
omaha2016
I am attempting to find alerts that where set by previous employees. Even after looking at all alerts and enabled ale...
by omaha2016 New Member in Splunk Enterprise Security 04-10-2019
0 1
0
1
rashid47010
link text We patch our OS last week and OS admin advise us to reboto the Indexers once. we have multistie scenerios....
by rashid47010 Communicator in Splunk Enterprise Security 04-09-2019
0 1
0
1
walsborn
I am new to the Splunk admin role and am having troubles with some errors. When a search is conducting I can see err...
by walsborn Path Finder in Splunk Enterprise Security 04-08-2019
0 2
0
2
jacqu3sy
Hi, Whats the best way to return events from a search after also checking they're not contained within another index...
by jacqu3sy Path Finder in Splunk Enterprise Security 04-08-2019
0 0
0
0
miront
I want to combine multiple notable events into a single search so I am using this: eval urgency=case(infection_count<...
by miront Explorer in Splunk Enterprise Security 04-08-2019
1 2
1
2
jacqu3sy
Hi, I have the following query, for returning the last time a device contained in a lookup logged to splunk by the ...
by jacqu3sy Path Finder in Splunk Enterprise Security 04-08-2019
0 3
0
3
jawaharas
Configuration: We have configured a lookup table under 'ESS Identity management' to maintain the list of users. The u...
by jawaharas Motivator in Splunk Enterprise Security 04-07-2019
0 3
0
3
adm_rashi
Hello All, I tried the below query and got the results as well but my concern is who is modifying, deleting or creat...
by adm_rashi New Member in Splunk Enterprise Security 04-02-2019
0 0
0
0
yemyslf
I am using tstats to search for some IP addresses. I'm trying to return the count of those IP addresses, which is eas...
by yemyslf Path Finder in Splunk Enterprise Security 04-02-2019
0 1
0
1
smithahc1966
I am trying to write a search which finds the addition or deletion to the log sources happened since last week by ind...
by smithahc1966 New Member in Splunk Enterprise Security 04-02-2019
0 1
0
1
hexerino
We encountered some issues when upgrading our clustered indexes infrastructure from 7.2.4 to 7.2.5. The upgrade proce...
by hexerino Explorer in Splunk Enterprise Security 04-02-2019
0 2
0
2
doodoodonk
The problem I am having is finding a way to write a rule that will be good enough to find a malicious child-process t...
by doodoodonk Engager in Splunk Enterprise Security 03-31-2019
0 5
0
5
burakatabay
Hello Splunkers, Trying to fix the Web data models in the CIM and would like to exclude a couple of IP addresses. Ho...
by burakatabay Path Finder in Splunk Enterprise Security 03-29-2019
0 1
0
1
chamjo
Hello guys: I'm going to get log from my firewall ,in order to see more firewall information in my splunk enterpris...
by chamjo New Member in Splunk Enterprise Security 03-29-2019
0 2
0
2
arlombar
Is it possible to rename auto-discovered fields? I can't seem to find a way to do this. I tried adding events to a da...
by arlombar Explorer in Splunk Enterprise Security 03-28-2019
0 1
0
1
tinanicole21
I was just wondering if anyone has figured out the correct syntax to use so you could click on a correlation search '...
by tinanicole21 New Member in Splunk Enterprise Security 03-28-2019
0 0
0
0
saurabhsumangat
My fields are not showing in additional field under incident review in Splunk. I want to take results obtained from t...
by saurabhsumangat New Member in Splunk Enterprise Security 03-28-2019
0 1
0
1
lakshman239
The latest add-on 4.6.0 installed on splunk 7.1.3, when restarted throws an the following error: Any plans to fix th...
by lakshman239 Influencer in Splunk Enterprise Security 03-28-2019
0 1
0
1
hexerino
Hi, I am trying to figure out how to pass a field value in the search to a macro which interprets it and does furthe...
by hexerino Explorer in Splunk Enterprise Security 03-28-2019
0 3
0
3
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...