We have a cluster with two search heads and two indexers. We need to install the EnterpriseSecurity app on the search heads. The question arises regarding the summary index and indexes created d...
Hi, We are using Splunk Enterprise on-premise. Now, I launched another one with a trial license and I would like to test Security features. However the app download is restricted unfortunately....
Hi, i got error after completed set up EnterpriseSecurity on my lab. First im using Windows but when want to setup EnterpriseSecurity always got Error in 'essinstall' command: (I...
I have installed the latest splunk with Splunk enterprisesecurity on it. I have worked with enterprisesecurity before, and there were some filters available to filter incidents, now in this v...
Hi at all, I installed EnterpriseSecurity 7.2.0 on Splunk 9.1.1 and I'm receiving the following message: Unable to initialize modular input "confcheck_es_bias_language_cleanup" defined in the a...
...erver.
Lets assume if i m ingesting a 300GB/day in splunk and i have 5 administrative users using search head then the highlighted below is good to follow.
If i am adding Enterprisesecurity...
Hi there, I'm looking to setup an automated email that will trigger any time a new alert comes into Incident Review in Splunk ES (using Splunk>enterprise). The idea is for the team to be n...
Greetings!!! How to updrade from 5.3.0 to SPlunk EnterpriseSecurity version 7.0, I am having splunk enterprise 7.2.6, Kindly advise & guide me how can i u...
hi folks, the scenario is like below - have Enterprisesecurity (ESS) in Splunk cloud + ESCU (content updates) as part of it - if we enable a ESCU detection it works all good. - we need to m...