...EnterpriseSecuritySuite) from etc/shcluster/apps to etc/apps folder Ran the upgrade command – (/opt/splunk/bin/splunkinstall app ./splunk-enterprise-security_620.spl -update 1) Ran the essinstall command as per the in...
Hi,
I use SplunkEnterpriseSecurity with ThreatIntelligence framework.
Splunk creates many notables 'Threat Activity Detected' but I'd like to add/remove/edit source types.
I have only events...
Splunk can collect a lot of the Amazon Web Services (AWS) data. But I see many items on Splunkbase for AWS technologies. Is there a complete list of apps and when to use each?
Hi I would like to add an additional ThreatIntelligence Feed to the collection of the Intelligence Downloads inEnterpriseSecurity. The Service-URL needs to have an authorization header t...
Palo Alto Networks Add-on 6.0.2 - fail to download threatintelligencefrom AutoFocus' MineMeld inSplunkEnterpriseSecurity
I installed Palo Alto Networks Add-on 6.0.2 and configured it to d...
Looking over the clients configuration for adding a lookup based source for EnterpriseSecurityThreatIntelligence, it appears to be configured correctly.
However I still see zero eventsin the d...
So within the EnterpriseSecurity App, there is the built-inthreat activity dashboard. One of panels shows your sourcetype(firewall) and all the hits the events off that source type match up with a...
..., allowing users to monitor and act on securityincidents and intelligence Does it means that Splunk ES works without any forwarder? How the correlaation is done beteween these addns and the enterprise...
Hello, I'm just having a bit of difficulty differentiating between SplunkEnterprise, ITSI, SOAR, UBA, and EnterpriseSecurity. It seems like they all do similar things. Do they a...
Need help on enterprisesecurity. Is there a way to create a standard TAXII Parser that can do correlation searches of logs coming from Maritime Transportation System ISAC & logs coming from S...