Hello,
I'm trying to force an app to use python 2.7 on a Splunk 8 withenterprisesecurity.
The config in server.conf is set to:
python.version = python3
Withthis setting my app doesn't work...
I have been trying to configure the Linux Auditd app to get it 100% functioning. Some of the panes are working and some are not. The app is not integrated withSplunkEnterpriseSecurity (ES) and r...
I have built an app (it contains eventtypes and tag) and have set it permission global.
Apart from ES app, all its eventtypes and tags are working properly in other apps(example: searching and r...
...he spelling of the app, or choose another from the following list: Environment: OS: Windows 2012 SplunkEnterprise 8.1.2 (Free) Windows Event Code Security Analysis V...
I'm using SplunkEnterprise 8.2.5 on Windows and using deployment server to push apps. There is currently no indexer configured in /etc/system/local/outputs.conf as we do all this in the app. O...
...isabled and are as follows:
Event Code = 4768
AND
krb tgt request result code = 0x12 or 0x6
Now, I'm having some trouble with syntax for this (note that the datamodel expanded while I was work...
Hello,
I'm having a strange problem where geoip works fine in Splunk search but not within the EnterpriseSecurityapp. In ES, I get the error "unknown search command 'geoip'". I can't figure o...