Splunk Enterprise

Splunk Enterprise
Community Activity
kuhnto
We are investigating various logging clients to send to our current log server.  Splunk UF is one.  We are in a long ...
by kuhnto New Member in Splunk Enterprise 05-02-2021
0 1
0
1
SamHTexas
How do I look up the computer name of the Splunk instance like Deployment server or a SH? I would like to view .conf ...
by SamHTexas Builder in Splunk Enterprise 04-30-2021
0 1
0
1
SamHTexas
Licensing best practices, need to trim it. I have Splunk Enterprise, a SOC team that uses ES. If you have taken measu...
by SamHTexas Builder in Splunk Enterprise 04-30-2021
0 0
0
0
markpdeakin
Hi Splunk Community,I am seeking assistance on what should be a relatively simple task - to drop/filter particular ev...
by markpdeakin Explorer in Splunk Enterprise 04-29-2021
0 3
0
3
pjAstroMan
Hi there I am a newby Splunk user trying to get a feel for the system.  I need to be able to export data in native Ex...
by pjAstroMan Explorer in Splunk Enterprise 04-29-2021
0 0
0
0
omershira
Hey all,We want to start analyzing sysmon information via Splunk (event logs)We did find applications here but it did...
by omershira Explorer in Splunk Enterprise 04-29-2021
0 0
0
0
perrinj2
I'm monitoring a Windows drive for any files ending in *.lrr and *.eve. This is because we have no control over where...
by perrinj2 Path Finder in Splunk Enterprise 04-28-2021
0 0
0
0
SamHTexas
Why oldest and most current data in _audit index is current via CLI on Deployment server & not current via GUI? The d...
by SamHTexas Builder in Splunk Enterprise 04-28-2021
0 0
0
0
roshankande
Hi community, Our organisation has a splunk enterprise deployment to which I am trying to connect programatically via...
by roshankande Loves-to-Learn in Splunk Enterprise 04-28-2021
0 0
0
0
SamHTexas
Where do I find documentation reg. how long Splunk is retaining audit logs? Can this be edited? Thank u.
by SamHTexas Builder in Splunk Enterprise 04-28-2021
0 9
0
9
khanh_le
HiCurrent we have Splunk Enterprise version 7.2.2 . I am planning to upgrade Splunk V 8What Splunk Enterprise version...
by khanh_le Engager in Splunk Enterprise 04-28-2021
0 1
0
1
shijinmts
HI teamWe were  analysing splunk tool for a while. We we very much impressed with the features available. Still we ne...
by shijinmts New Member in Splunk Enterprise 04-27-2021
0 0
0
0
kozanic_mg
We have a situation where we need to have General day to day admin Role and an Elevated admin role.Day to Day will al...
by kozanic_mg Explorer in Splunk Enterprise 04-26-2021
0 0
0
0
jonathandevos
I can't seem to get my Watchguard Firebox integrated with our Splunk Enterprise.  I have followed the integration gui...
by jonathandevos Loves-to-Learn in Splunk Enterprise 04-26-2021
0 0
0
0
kozanic_mg
We are deploying SHC into AWS via  pipeline code and attempting to configure SAML integration as part of the build bu...
by kozanic_mg Explorer in Splunk Enterprise 04-25-2021
0 2
0
2
Siddharth
HI All ,I am preparing for splunk admin exam and I want to know what happens when splunk license expires in 8.1.1 doe...
by Siddharth Path Finder in Splunk Enterprise 04-25-2021
0 0
0
0
bishtk
Hi All,We  are having multisite splunk architecture (version 8.1.0) and using LDAP for users authentication.We are no...
by bishtk Communicator in Splunk Enterprise 04-24-2021
0 3
0
3
patelmc
We are moving from one datacenter to another one which require to change IP addresses of all Splunk instances. All of...
by patelmc Explorer in Splunk Enterprise 04-23-2021
0 0
0
0
mani9059
Hi ,I am trying very hard to get the API for disabling the alerts in splunk.my view in splunk:APP: xyzAlert name: tes...
by mani9059 Engager in Splunk Enterprise 04-23-2021
0 0
0
0
fatihah
Currently, I already filter the Windows event logs for only Windows Security logs. However, windows logs have take up...
by fatihah Engager in Splunk Enterprise 04-22-2021
0 3
0
3
SamHTexas
What is the path to the etc folder on windows or Unix hosts. How do I copy the etc folder for backing up purposes? Pl...
by SamHTexas Builder in Splunk Enterprise 04-22-2021
0 5
0
5
Hemnaath
 When I am trying to validate the connection  the validation is taking time and finally popping out a message saying ...
by Hemnaath Motivator in Splunk Enterprise 04-22-2021
0 3
0
3
jip31
helloIn the stats command below, i try to retrieve the _time values (which is the Splunk timestamp) corresponding to ...
by jip31 Motivator in Splunk Enterprise 04-22-2021
0 5
0
5
utkarsh
Hello everyone,I am getting event data inside my splunk.  I want to query data ( logins by country) on splunk search,...
by utkarsh Explorer in Splunk Enterprise 04-22-2021
0 4
0
4
anandhalagaras1
Hi All,Based on this query I want to filter out wineventlog before ingesting into Splunk. So that i can save some lic...
by anandhalagaras1 Contributor in Splunk Enterprise 04-21-2021
0 4
0
4
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors