Trying to modify this default correlation search: | from inputlookup:access_tracker | stats min(firstTime) as firstTime,max(lastTime) as lastTime by user | where ((now()-'lastTime')/86400)>90 I ...
All, I have a threat intelligence application installed on my Splunk Cloud. I recently brought online Splunk enterprisesecurity. Why is it that the application is not installed o...
Hi.
Does anyone know if Multitenancy can be accomplished with a Single Instance of EnterpriseSecurity?
I have searched and read a lot of info but havent came with a definitive answer yet....
Hi in my company they recently migrated to Spunk(EnterpriseSecurity) from QRador so installation part is done rule creation is done
and Vulnerability center , asset data feed,user data feed,t...
Hello All, I'm having an issue where I am unable to create new correlation searches. I get the following error: There was an error saving the correlation search: In handler 'savedsearch': ...
Hi splunkers, I run splunk cloud and recently worked with Support to install Splunk EnterpriseSecurity. Within splunk enterprisesecurity how do I confirm that it is correlating all of my i...
We are using ES and I was wondering if all the data models\lookups and enriched data available when searching from a non ES search head?
our deployment has a ES search head and then 2 clustered se...
Hi,
I have installed a splunk enterprise trial and also requested Splunk EnterpriseSecurity. I noticed that when I try a simple search "fail* password" in both platform, the fields that a...
Deployment: on premise, distributed
Splunk Platform version : 7.2.6
EnterpriseSecurity version : 5.3.0
Hello,
We are trying to refine the roles to be granted to our SOC team based on a "l...
Hello,
I have read through your hardware requirements for Splunk Enterprise. We will be purchasing the EnterpriseSecurity (ES) app and have a dedicated Search server for ES. Question, are the h...