Activity Feed
- Posted Re: Splunk ES Incident Review Notable Events Don't Match Correlation Search on Splunk Enterprise Security. 08-11-2021 12:59 PM
- Posted Re: Grouping Notable Events from MLTK alerts on Splunk Enterprise Security. 08-06-2021 10:01 AM
- Posted Re: ES Identity: prevent merge for email field on Splunk Enterprise Security. 08-06-2021 09:56 AM
- Posted Re: How do I access a list of Saved searches for different apps. To change their timing in ES? Any helpful SPLs ? Thank on Splunk Enterprise Security. 07-27-2021 10:01 AM
- Got Karma for Re: How do I access a list of Saved searches for different apps. To change their timing in ES? Any helpful SPLs ? Thank. 07-26-2021 06:45 PM
- Posted Re: How do I access a list of Saved searches for different apps. To change their timing in ES? Any helpful SPLs ? Thank on Splunk Enterprise Security. 07-26-2021 05:38 PM
- Posted Re: Easy notables search - top owners and top alerts per owner on Splunk Enterprise Security. 07-12-2021 09:09 AM
- Posted Re: Has any great person here written a Back up / DR for Splunk ES? Any guidance is much appreciated. on Splunk Enterprise Security. 07-12-2021 09:02 AM
- Got Karma for Re: ES Notable events add a link on "next steps" form. 07-12-2021 01:32 AM
- Posted Re: ES Notable events add a link on "next steps" form on Splunk Enterprise Security. 07-09-2021 10:13 AM
- Posted Re: ES Notable events add a link on "next steps" form on Splunk Enterprise Security. 07-08-2021 09:10 AM
- Posted Re: Need your expert advice about Splunk Ent. & Enterprise Security (ES) Backups + Disaster Recover + HA advice plea on Splunk Enterprise Security. 07-02-2021 09:32 AM
- Posted Re: no latest update for ESCU on Splunk Enterprise Security. 06-17-2021 07:08 PM
- Posted Re: Risk Based alerting in SPLUNK ES on Splunk Enterprise Security. 06-15-2021 08:55 AM
- Posted Re: Why does latest version of ES CU app indicates exploring Analytical Stories through ES or Sec Essentials App ? on Splunk Enterprise Security. 06-02-2021 09:03 AM
- Posted Re: How do I backup the Splunk Enterprise Security app. What components needs to be backed up and how often? on Splunk Enterprise Security. 05-11-2021 10:33 AM
- Posted Re: Disable identitymerge in older enterprise security? on Splunk Enterprise Security. 03-25-2021 09:14 AM
- Posted Re: Disable identitymerge in older enterprise security? on Splunk Enterprise Security. 03-24-2021 06:21 PM
- Posted Re: Where do I find already built in Dashboards in Splunk Enterprise & ES on Splunk Enterprise Security. 03-17-2021 09:26 AM
- Posted Re: Please help me learn standard built in features of Splunk Enterprise Security App. (ES) on Splunk Enterprise Security. 03-16-2021 09:15 AM
Topics I've Started
No posts to display.
02-19-2021
03:07 PM
1 Karma
If you click on a Correlation Search (for example) such as (chosen at random) "ESCU - Detect Windows DNS SIGRed via Splunk Stream - Rule"... you can scroll down to Adaptive Response Actions and click +Add New Response Action. So that's under Configure -> Content -> Content Management -> <name of correlation search>
... View more
- Tags:
- if
02-18-2021
10:15 AM
1 Karma
Does it have to be a line chart? Would the audit dashboards show similar results? https://docs.splunk.com/Documentation/ES/6.4.1/User/Audit#Incident_Review_Audit https://docs.splunk.com/Documentation/ES/6.4.1/User/Audit#Investigation_Overview
... View more
02-17-2021
09:36 AM
I don't know the answer for sure, but do you need to include the data set? For example: Endpoint.Ports, Endpoint.Processes, Endpoint.Services, or Endpoint.Filesystem? https://docs.splunk.com/Documentation/CIM/4.18.0/User/Endpoint#Search_Example
... View more
02-11-2021
08:34 AM
Hi, Is this the part you're doing? https://docs.splunk.com/Documentation/ES/6.4.1/Admin/Verifyassetandidentitydata Based on these? https://docs.splunk.com/Documentation/ES/6.4.1/Admin/Addassetandidentitydata#Use_LDAP_to_register_data_in_Asset_and_Identity_Manager
... View more
02-04-2021
09:07 AM
Let me know if this helps: https://docs.splunk.com/Documentation/ES/6.4.1/Admin/Troubleshootnotables
... View more
02-01-2021
09:08 AM
It probably depends on which version of the ES Content Updates app you have installed. I have 3.9.1. I see ColdRoot MacOS RAT Analytic Story & Malware Use Case for Alerts. I don't see any for Certificates.
... View more
01-29-2021
10:32 AM
In the Use Case Library... you can filter on the data model to see if there's a matching analytic story or use case: https://<splunk:port>/splunk-es/en-US/app/SplunkEnterpriseSecuritySuite/ess_use_case_library the filters are Framework Mapping, Data Model, App, In Use, Bookmarked Docs: https://docs.splunk.com/Documentation/ES/6.4.1/Admin/Usecasecontentlibrary
... View more
01-28-2021
10:46 AM
1 Karma
Here are some other tips for troubleshooting notable events: https://docs.splunk.com/Documentation/ES/6.4.1/Admin/Troubleshootnotables
... View more
01-28-2021
10:44 AM
You could use the Use Case Library to see which data sources and source types map to certain types of use cases, based on what you want to do: https://docs.splunk.com/Documentation/ES/6.4.1/Admin/Usecasecontentlibrary#Determine_which_Analytic_Stories_to_configure
... View more
01-28-2021
09:56 AM
You're correct, there's no approval status in the application_protocol_lookup. Docs updated, thanks! The status part for the ports in use by the apps is in interesting_ports_lookup: is_required is_prohibited is_secure
... View more
01-28-2021
09:36 AM
It's for internal auditing. From the ES menu bar, if you go to Audit > View Audit... it shows the "views" (or pages in the ES app) where your admins/analysts/users are looking most often. The Expected Views lookup is configurable, so you can add views to it if you would expect that they should be monitored daily, and then you can see if they are. You would go to Configure > Content > Content Management, then search for Expected Views, and then edit it from there.
... View more
12-23-2020
10:03 AM
... so you would have to download the ones that you need from Splunkbase instead.
... View more
12-23-2020
10:01 AM
As of ES 6.2, almost all of the add-ons have been removed from the installer: https://docs.splunk.com/Documentation/ES/6.2.0/RN/Enhancements https://docs.splunk.com/Documentation/ES/6.2.0/RN/Enhancements#Add-ons
... View more
12-22-2020
03:51 PM
Your syntax looks correct based on the docs: https://docs.splunk.com/Documentation/Splunk/8.1.1/RESTTUT/RESTsearches#Example:_Create_a_search Are you using an on-prem instance or a cloud instance? There might be some access requirements and limitations: https://docs.splunk.com/Documentation/Splunk/latest/RESTTUT/RESTandCloud
... View more
12-22-2020
03:34 PM
Hi, There's a new page in the docs about troubleshooting missing notable events in Splunk Enterprise Security. Maybe one of these tips will help: https://docs.splunk.com/Documentation/ES/6.4.0/Admin/Troubleshootnotables
... View more
12-22-2020
03:30 PM
Yes, you can do that. You can start an investigation & then you can manually create a notable event called "started an investigation" (or whatever you like): https://docs.splunk.com/Documentation/ES/6.4.0/Admin/Createnotablesmanually#Create_a_notable_event_from_scratch & you can see it in Incident Review & add it to your investigation.
... View more
12-22-2020
02:48 PM
Update to my previous answer... If you're including the ES option, the numbers should match. Whatever volume your license is, use the same number for ES volume.
... View more
12-21-2020
09:39 AM
You could use the investigation workbench. It's like ticket tracking & collaborating on investigations for assets, identities, or artifacts involved in a potential security incident: https://docs.splunk.com/Documentation/ES/6.4.0/User/InvestigationWorkbench
... View more
12-15-2020
04:37 PM
Hi! For this step? > 2. Current License(s) - Core is required, future requirements will be accounted for later. I believe that only the Splunk Enterprise core license size is required & the other fields are optional. Splunk Enterprise Security doesn't have its own physical license, but it requires a Splunk Enterprise license or Splunk Cloud subscription. You just need more like an entitlement term associated with the account to download ES from Splunkbase (is what I last heard in August).
... View more
12-11-2020
12:05 PM
Oh! Sorry, I thought I saw "merging" assets. My answer might not apply to your question 🙂
... View more
12-11-2020
12:02 PM
1 Karma
Which version of ES are you using? If ~6.0 or higher, you could rank them: https://docs.splunk.com/Documentation/ES/6.4.0/Admin/Assetlookupconfiguration#Rank_the_order_for_merging_assets Any new asset list gets added to the bottom of the list by default. You can rank the order of this list to determine priority for merging assets. If an asset exists in multiple source files as a single value or exists multiple times in the same source file, this ranking is the weighted order for merging them.
... View more
12-09-2020
03:29 PM
Which version of ES are you using? Is correlation enabled? Correlation is the part that enriches events with your asset and identity data at search time: https://docs.splunk.com/Documentation/ES/6.4.0/Admin/Correlationsetup
... View more
12-09-2020
12:01 PM
That's a good question. I could be wrong, but I don't think there's a way to do it from the Splunk Web UI. You should probably post that as a feature enhancement on https://ideas.splunk.com/.
... View more
12-02-2020
03:48 PM
Hi! I'm late to the party with this answer, but yes, you can use Endpoint for that. The Endpoint doc has been updated with further details... The Endpoint data model is for monitoring endpoint clients including, but not limited to, end-user machines, laptops, and bring your own devices (BYOD). If an event is about an endpoint process, service, file, port, and so on, then it relates to the Endpoint data model. For administrative and policy types of changes to infrastructure security devices, servers, and endpoint detection and response (EDR) systems, see Change.Endpoint in the Change data model. https://docs.splunk.com/Documentation/CIM/4.18.0/User/Endpoint
... View more
12-02-2020
03:21 PM
I agree with nickhillscpl & it's one of the options listed in the doc: https://docs.splunk.com/Documentation/ES/6.4.0/Admin/Verifyassetandidentitydata
... View more