Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
infosec_kicb
Hello all! resently i downloaded Check Point App for Splunk. I configured in input.conf in order to force all Chech...
by infosec_kicb New Member in Splunk Enterprise Security 02-22-2019
0 4
0
4
koshyk
hi anyone created "custom" roles in Enterprise Security and re-used the notables dashboard (security events) ? We ha...
by koshyk Super Champion in Splunk Enterprise Security 02-22-2019
0 3
0
3
bhaskarasplunk
I want to pass a token from one panel to another panel. I mean, if I give one input in the drop down, it has to updat...
by bhaskarasplunk Explorer in Splunk Enterprise Security 02-21-2019
0 2
0
2
sonin
Dear ALL , I am searching a procedure to pull and update the incidents from Symantec MSS created by their SOC they...
by sonin New Member in Splunk Enterprise Security 02-20-2019
0 0
0
0
tmiller_splunk
Does this TA Support Nessus Home installations? I've tried to use Tenable.io and authentication seems to work but no...
by tmiller_splunk Splunk Employee Splunk Employee in Splunk Enterprise Security 02-19-2019
0 2
0
2
iomega311
I am trying to create a query where there are two different searches that each produce a point in time for each devic...
by iomega311 Explorer in Splunk Enterprise Security 02-19-2019
0 2
0
2
map000
I installed Fortinet Fortigate Add-on for Splunk 1.6.0 and Fortinet Fortigate App for Splunk 1.4. Sourcetypes are ide...
by map000 New Member in Splunk Enterprise Security 02-18-2019
0 3
0
3
04cjm
I have setup a few correlated events which currently are showing up in the incident review console as urgency (unknow...
by 04cjm Engager in Splunk Enterprise Security 02-14-2019
1 3
1
3
vj8210
Hi, I'm querying a datamodel X and I need to append results with same fields names from datamodel xx using. I'm try...
by vj8210 Explorer in Splunk Enterprise Security 02-13-2019
1 2
1
2
HannanPervez
Hello, I am trying to create alerts for all outbound DNS queries which do not match the top one million domains as p...
by HannanPervez Explorer in Splunk Enterprise Security 02-13-2019
0 5
0
5
godawatnikunj19
by default, where from threat Intelligence feed downloaded in splunk ?
by godawatnikunj19 New Member in Splunk Enterprise Security 02-12-2019
0 1
0
1
kamoenix
Hi Everyone I'm having trouble with one of the alerts in Enterprise Security which is causing a lot of noise and fal...
by kamoenix New Member in Splunk Enterprise Security 02-11-2019
0 3
0
3
hoytn
Hello, I'm looking into a way to discover following scenario in my ingested logs: some user logged out and didn't lo...
by hoytn Explorer in Splunk Enterprise Security 02-11-2019
0 2
0
2
lball
I'm getting a scripting error on our Enterprise Security server every hour: msg="A script exited abnormally" input="...
by lball Explorer in Splunk Enterprise Security 02-11-2019
0 3
0
3
lth186
Hello, I'm trying to correlate events from 2 different source types, and 2 searches for example: sourcetypeA has fi...
by lth186 New Member in Splunk Enterprise Security 02-10-2019
0 8
0
8
apple143
Hi, Thanks for coming to my question. I am having trouble using javascript SDK. I cannot understand what is "my s...
by apple143 Engager in Splunk Enterprise Security 02-09-2019
0 0
0
0
arlombar
I have a search in which is generating results when I have it set as an alert and is successfully creating and event ...
by arlombar Explorer in Splunk Enterprise Security 02-08-2019
0 4
0
4
shiv1593
Hi All, I have a use case where I want to send replies using a separate email address than the default address of Sp...
by shiv1593 Communicator in Splunk Enterprise Security 02-08-2019
0 13
0
13
jacqu3sy
Hi, When having lookups contained within an app, is it possible to set user permissions at the 'app' level as oppose...
by jacqu3sy Path Finder in Splunk Enterprise Security 02-07-2019
0 2
0
2
wrosadj
Would any one know how to look up the name of a person who owns a notable event using the owner field? This is my sea...
by wrosadj New Member in Splunk Enterprise Security 02-07-2019
0 2
0
2
daniel333
All, I have this indexes.conf and added a frozen archive. The path is fully readable and writable by the Splunk use...
by daniel333 Builder in Splunk Enterprise Security 02-05-2019
0 2
0
2
jasonportico
Greetings - I'm using BlueCoat ThreatPulse as a web filter ('cloud' based). The only method to pull their logs is vi...
by jasonportico Engager in Splunk Enterprise Security 02-05-2019
0 3
0
3
Mahesh08
Do we have an app/add-on for citrix netscaler load balancer for splunk 7.0 above versions . otherwise will the curren...
by Mahesh08 New Member in Splunk Enterprise Security 02-04-2019
0 2
0
2
MikeBertelsen
I have a Splunk instance with a Search Head (SH) and two load balanced Indexers. There are two Heavy Forwarders (HF) ...
by MikeBertelsen Communicator in Splunk Enterprise Security 02-04-2019
0 5
0
5
ernst_young_chn
Hello All, I am currently working on integration of Threatquotient feed to Splunk. I am successful in getting the ...
by ernst_young_chn Engager in Splunk Enterprise Security 02-04-2019
0 2
0
2
Get Updates on the Splunk Community!

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...