Splunk Enterprise Security

Splunk Enterprise Security
Community Activity
eugenolteanu
Hello, I'm trying to figure out a search that will parse through all events from a specific sourcetype. For each un...
by eugenolteanu New Member in Splunk Enterprise Security 02-27-2019
0 3
0
3
zekiramhi
Hello, Is there a way to validate the fields used in the datamodel by how compliant they are with the current setup?...
by zekiramhi Path Finder in Splunk Enterprise Security 02-27-2019
0 6
0
6
shacharh
Hi, I'm working on an add-on for Splunk. I added an alert action, and I'm adding some fields to it. How can I add a ...
by shacharh New Member in Splunk Enterprise Security 02-27-2019
0 7
0
7
cnoulin
Hello, i have made an alert as follow : [|inputlookup admin_groups.csv | table "query" as Group_Name ] | search Eve...
by cnoulin Explorer in Splunk Enterprise Security 02-27-2019
0 8
0
8
wendtb
I am trying to whitelist events from a specific server using IP and hostname. I am running into 2 issues. I have dif...
by wendtb Path Finder in Splunk Enterprise Security 02-26-2019
0 5
0
5
PruthviPGowda
Hi All, Does a license key(or file) is being required to “activate” the Splunk Enterprise Security App? Looking for...
by PruthviPGowda New Member in Splunk Enterprise Security 02-26-2019
0 1
0
1
impsk
Hello Folks, I have a concern with one of my customer using Splunk Enterprise Security App,they mentioned the don’t ...
by impsk New Member in Splunk Enterprise Security 02-26-2019
0 1
0
1
bhaskarasplunk
Hi, I have four options in a drop down--- Highest,Lowest ,Top 5 and Least 5. Each option has a query: For example ...
by bhaskarasplunk Explorer in Splunk Enterprise Security 02-26-2019
0 2
0
2
raghu_vedic
Hi, We are facing this issue frequently in splunk search head. Please help me. Unable to distribute to peer named ...
by raghu_vedic Path Finder in Splunk Enterprise Security 02-25-2019
0 2
0
2
danielearangiom
How can I monitor if all correlations open incidents into "Incident Reviews" in Splunk ES correctly?
by danielearangiom Explorer in Splunk Enterprise Security 02-25-2019
0 2
0
2
sahiltcs
We created Dashboard in Splunk enterprise security where we can see the commands status and risk score for those comm...
by sahiltcs Path Finder in Splunk Enterprise Security 02-25-2019
0 8
0
8
rajpingale123
hello, how do i monitor network data using netflow analyzer? i have installed add on of netflow analyzer.please tell ...
by rajpingale123 Engager in Splunk Enterprise Security 02-22-2019
0 1
0
1
MatthewH007
I was looking for a way to view WHAT exactly was audited when someone changes a ROLE or USER (capabilities, inherited...
by MatthewH007 Path Finder in Splunk Enterprise Security 02-22-2019
2 0
2
0
sivasankarketin
Guys, Any idea of writing a splunk query to find the malicious command and control traffic using Cisco IPS logs. We ...
by sivasankarketin New Member in Splunk Enterprise Security 02-22-2019
0 2
0
2
crumblecat88
Hi, I'm getting varied results in Splunk when I investigate an IP address' location. Splunk might say "Netherlands",...
by crumblecat88 Engager in Splunk Enterprise Security 02-22-2019
0 1
0
1
infosec_kicb
Hello all! resently i downloaded Check Point App for Splunk. I configured in input.conf in order to force all Chech...
by infosec_kicb New Member in Splunk Enterprise Security 02-22-2019
0 4
0
4
koshyk
hi anyone created "custom" roles in Enterprise Security and re-used the notables dashboard (security events) ? We ha...
by koshyk Super Champion in Splunk Enterprise Security 02-22-2019
0 3
0
3
bhaskarasplunk
I want to pass a token from one panel to another panel. I mean, if I give one input in the drop down, it has to updat...
by bhaskarasplunk Explorer in Splunk Enterprise Security 02-21-2019
0 2
0
2
sonin
Dear ALL , I am searching a procedure to pull and update the incidents from Symantec MSS created by their SOC they...
by sonin New Member in Splunk Enterprise Security 02-20-2019
0 0
0
0
tmiller_splunk
Does this TA Support Nessus Home installations? I've tried to use Tenable.io and authentication seems to work but no...
by tmiller_splunk Splunk Employee Splunk Employee in Splunk Enterprise Security 02-19-2019
0 2
0
2
iomega311
I am trying to create a query where there are two different searches that each produce a point in time for each devic...
by iomega311 Explorer in Splunk Enterprise Security 02-19-2019
0 2
0
2
map000
I installed Fortinet Fortigate Add-on for Splunk 1.6.0 and Fortinet Fortigate App for Splunk 1.4. Sourcetypes are ide...
by map000 New Member in Splunk Enterprise Security 02-18-2019
0 3
0
3
04cjm
I have setup a few correlated events which currently are showing up in the incident review console as urgency (unknow...
by 04cjm Engager in Splunk Enterprise Security 02-14-2019
1 3
1
3
vj8210
Hi, I'm querying a datamodel X and I need to append results with same fields names from datamodel xx using. I'm try...
by vj8210 Explorer in Splunk Enterprise Security 02-13-2019
1 2
1
2
HannanPervez
Hello, I am trying to create alerts for all outbound DNS queries which do not match the top one million domains as p...
by HannanPervez Explorer in Splunk Enterprise Security 02-13-2019
0 5
0
5
Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...