Activity Feed
- Posted Re: transfer community's account on Feedback. 10-24-2024 10:42 AM
- Posted Re: URGENT: Splunk Threat Hunting Course Not Visible on Training + Certification Discussions. 10-02-2024 11:26 AM
- Got Karma for Re: Upgrade or install UF agents on endpoints via Deployment server. 09-25-2024 11:16 PM
- Posted Re: Upgrade or install UF agents on endpoints via Deployment server on Feedback. 09-23-2024 08:49 AM
- Karma Re: Difference between last(X) and latest(X) for dart. 09-12-2024 11:46 AM
- Karma Re: How to troubleshoot if splunk is down for woodcock. 09-04-2024 12:49 PM
- Karma Re: How to troubleshoot if splunk is down for Azeemering. 09-04-2024 12:49 PM
- Karma Re: Where can I download my Splunk certifications? for javiergn. 08-21-2024 10:27 AM
- Posted Re: There’s a New Certification in Town: Splunk Certified Cybersecurity Defense Engineer on Training & Certification Blog. 08-12-2024 10:06 AM
- Posted Re: virus total integration with Splunk SIEM on All Apps and Add-ons. 07-10-2024 08:04 AM
- Posted Re: How do I fix in curl requests: curl(77) error? on Splunk Enterprise. 07-03-2024 11:49 AM
- Karma Re: How do I fix in curl requests: curl(77) error? for comcordriro. 07-03-2024 11:48 AM
- Posted Re: Splunk CAC Authentication not working on Security. 06-14-2024 03:30 PM
- Posted Re: Which properties are available for a Universal Forwarder in Props/Transforms ? on Getting Data In. 06-11-2024 10:17 AM
- Karma Re: Which properties are available for a Universal Forwarder in Props/Transforms ? for martin_mueller. 06-11-2024 10:13 AM
- Karma US Children's Hospitals for rawltide. 06-10-2024 10:52 PM
- Karma The Splunk Global Broadcast Community Dashboard Challenge Official Rules for JenniferBrown. 06-06-2024 10:35 AM
- Karma Re: Can I attend .conf interactive workshops virtually? for VatsalJagani. 06-05-2024 09:02 AM
- Got Karma for Re: Splunk visualization report ?. 06-04-2024 11:02 PM
- Posted Re: Perform a cidrmatch against a network CIDR retrieved from an inputlookup on Splunk Search. 06-04-2024 09:31 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
2 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
1 | |||
0 | |||
0 | |||
0 |
10-02-2024
11:26 AM
Volston, Can you use this link: https://education.splunk.com/Saba/Web_spf/NA10P2PRD105/app/me/learningeventdetail;spf-url=common%2Fledetail%2Fcours000000000016580%3FfromAutoSuggest%3Dtrue I can see the class. If not, there must be a requirement attached to the class. I am certified with ES and took the test too.
... View more
Solved: Install Universal forwarder from Splunk Deployment... - Splunk Community Here is something that might help.
... View more
08-12-2024
10:06 AM
Yes. It's beta. I took at .conf 24. I don't have the results yet.
... View more
07-10-2024
08:04 AM
I don't see the attachment. Have you looked at the index = _internal for log_level IN (WARN, ERROR)
... View more
07-03-2024
11:49 AM
Wow! I've encountered the same. Thanks for posting.
... View more
06-14-2024
03:30 PM
So, there is two ways to do this CAC authentication. SAML or LDAP trusted methods. Before, I thought PKI was just one option but, SAML open up another option. I hope this helps: Configure single sign-on with SAML - Splunk Documentation
... View more
06-11-2024
10:17 AM
Here are the latest props.conf setting at 9.2.1 on the universal forwarder: (json file parsing works g8 with this option) EVENT_BREAKER_ENABLE = <boolean> EVENT_BREAKER = <regular expression> LB_CHUNK_BREAKER = <regular expression> force_local_processing = <boolean> * new * Forces a universal forwarder to process all data tagged with this sourcetype locally before forwarding it to the indexers. * Data with this sourcetype is processed by the linebreaker, aggerator, and the regexreplacement processors in addition to the existing utf8 processor. * Note that switching this property potentially increases the cpu and memory consumption of the forwarder. * Applicable only on a universal forwarder. * Default: false
... View more
06-04-2024
09:31 AM
Additional idea on this thought is based on baseline of probing network. You can use this information to assign a risk base alert. Just a thought...
... View more
06-03-2024
10:18 AM
The version doesn't matter for the certification. You need to able to answer the core concept questions. Ex: I study with 7.1 but certified with 9.1
... View more
06-03-2024
10:14 AM
1 Karma
I would use the note or word has number to show viz. hope that helps.
... View more
05-31-2024
07:01 AM
Do you have access to the Udemy via company you're working for? If not, you buy the class I purchased to get my certification in Udemy. I found it very helpful. It was rank the highest. In addition, you can request additional 30 days from education. But that will be last one. Hope that was helpful.
... View more
05-30-2024
03:17 PM
how long was gap between two periods? If it's more than 30 days, that's your problem. You have to email education to reset the clock. They will only do it once.
... View more
05-28-2024
09:17 AM
It appears the problem still around. I am upgrading to 7.3.1 and still getting the error. I had to use the CLI option to upgrade.
... View more
05-24-2024
12:24 PM
1 Karma
The value that are return is without quotes. Hope that helps.
... View more
05-21-2024
08:21 AM
2 Karma
I have dashboard that doesn't exist on the internet. It shows the user session activities on the dashboard for windows, gateway, and Linux. It also shows the activities via interactive actions show privilege escalation and process running. This was created to answer external audit asks based NIST 800 -53. Would dashboard qualify for the contest or any of the super session on the .conf on the main conference floor? (I had to mask environment information) Here is the windows audit GPO required to monitor the session correctly.
... View more
05-06-2024
11:03 AM
I would open a ticket with Splunk Support. That should be working correctly unless someone did something with the permissions Or validate that you have access to the data overview that creates the dashboard. What version of ES are you using?
... View more
05-06-2024
10:59 AM
you have to search and index the json by branch and nodes. If you need the SPL, let me know.
... View more
04-21-2024
05:50 PM
1 Karma
You have to coordinate with your sales team for free classes or training credits. Or you can take Udemy class for $50 or you company might have free classes with Udemy.
... View more
04-21-2024
05:33 PM
Are you registered with a company email address or gmail.com email address?
... View more
04-16-2024
12:22 PM
Here are the setting that you can enable on the log.conf to get more detail logging. $splunk_install_dir$/etc/log.conf category.X509=DEBUG
category.UiAuth=DEBUG Post the error message here or call support.
... View more
03-15-2024
02:16 PM
I'd figure it out. It's saving the report with the Visualization tab. Thanks for your help in point me towards the right direction.
... View more