Activity Feed
- Got Karma for Re: operation:"copying source to destination", error:"Access is denied.". a month ago
- Got Karma for Bucket replication issues - No possible srcs for replication. 08-26-2021 01:26 PM
- Posted cannot change user and/or app context of a report that is embedded on Knowledge Management. 05-06-2021 03:57 AM
- Posted Re: How to configure index settings to index data directly in S3 buckets/smartstore ? on Getting Data In. 05-05-2021 06:48 PM
- Posted How to configure index settings to index data directly in S3 buckets/smartstore ? on Getting Data In. 05-04-2021 05:38 PM
- Posted Is there any Splunk recommended best practice for ingesting Netflow data ? on Getting Data In. 05-03-2021 09:16 PM
- Got Karma for How to configure input in DB Connect v3.1.2 for Splunk Add-on for Microsoft SQL Server using template mssql:audit ?. 03-01-2021 04:55 PM
- Posted Re: What is the recommended logging requirement for Linux OS from Splunk ES perspective ? on Splunk Enterprise Security. 02-04-2021 01:54 PM
- Posted What is the recommended logging requirement for Linux OS from Splunk ES perspective ? on Splunk Enterprise Security. 02-03-2021 09:18 PM
- Posted Need help to find specific auth logs for Linux OS on Getting Data In. 02-01-2021 12:31 AM
- Posted Re: Is there any ES Analytical Story or Usecase for Certificates and Alerts datamodel ? on Splunk Enterprise Security. 01-31-2021 04:22 AM
- Posted Is there any ES Analytical Story or Usecase for Certificates and Alerts datamodel ? on Splunk Enterprise Security. 01-28-2021 11:48 PM
- Posted Application Protocols list in ES - unclear in documentation on Splunk Enterprise Security. 01-28-2021 02:30 AM
- Posted What is the actual use of Expected Views lookup ? on Splunk Enterprise Security. 01-28-2021 02:23 AM
- Posted How does ESCU app exactly maps Analytical Stories against CIS Controls ? on Splunk Enterprise Security. 01-12-2021 03:43 AM
- Posted Is there any automated way to check or validate magix six parsing attributes have been configured ? on Getting Data In. 01-09-2021 05:28 PM
- Posted Re: Accelerating CIM Validation (S.o.S.) datamodel results in error on Splunk Enterprise Security. 01-06-2021 04:09 PM
- Posted Re: SSL Certificate Checker: Which extensions are supported? on All Apps and Add-ons. 01-05-2021 02:17 PM
- Posted Strategies for populating watchlist field in Assets and Identity Framework on Splunk Enterprise Security. 01-04-2021 05:31 AM
- Posted Accelerating CIM Validation (S.o.S.) datamodel results in error on Splunk Enterprise Security. 01-04-2021 05:01 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 |
05-06-2021
03:57 AM
There is a saved search which has been orphaned. When I attempted to reassign it to another user like admin or nobody, it didn't let me and showed the below warning message. cannot change user and/or app context of a report that is embedded
... View more
05-05-2021
06:48 PM
What if we just reduce the maxhotbuckets attribute to - 0 or change other hotbucket attribute like maxHotSpanSecs to 0, wouldn't just skip hot bucket and roll to warm bucket which would essentially get stored on S3 ? Alternatively, what if we configure S3 storage for hot buckets ?
... View more
05-04-2021
05:38 PM
Is there a way to skip hot buckets (local storage) and ingest/index data directly into smartstore (s3 buckets) ?
... View more
- Tags:
- smartstore
05-03-2021
09:16 PM
For Syslog, Splunk recommends using a dedicated syslog server. So, for Netflow data, is there any particular best practices for ingesting into Splunk ? Can I still continue using syslog server even for Netflow data or use Splunk stream app ? Please advise. Thanks.
... View more
Labels
02-04-2021
01:54 PM
Our needs are that we want to onboard security relevant logs from Linux OS and looking for some standard Linux auditing recommendations or just what Splunk suggests. Just like how Microsoft has provided for Windows OS like https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/audit-policy-recommendations
... View more
02-01-2021
12:31 AM
Can someone please guide how I can collect the following logs from Linux systems ? changes to account privileges. unsuccessful login and log off events for privileged accounts. any access attempts using deactivated accounts Any help on this would be highly appreciated.
... View more
Labels
- Labels:
-
Linux
01-31-2021
04:22 AM
I am aware of that and there are no use cases specific to Certificates and Alerts datamodel. I was wondering if anyone here has developed any use cases for these ?
... View more
01-28-2021
11:48 PM
Looking to find what ES usecases are there that use Certificate and/or Alert datamodels
... View more
Labels
- Labels:
-
using Enterprise Security
01-28-2021
02:30 AM
The documentation for Application Protocol list in ES states "The Application Protocols list is a list of port and protocol combinations and their approval status in your organization" and shows fields available in the file. Field Description dest_port The destination port number. Must be a number from 0 to 65535. transport The protocol of the network traffic. For example, icmp, tcp, or udp. app The name of the application using the port. But where is the field for approval status ? or am I interpreting it in wrong way ?
... View more
Labels
- Labels:
-
using Enterprise Security
01-28-2021
02:23 AM
Splunk doc says, Expected Views list specifies Splunk Enterprise Security views that are monitored on a regular basis. But what are these views monitored for ? What do I need to actually use this for ? Whats the usecase behind it ?
... View more
Labels
- Labels:
-
using Enterprise Security
01-12-2021
03:43 AM
Some context here - When I go to ESCU app and filter down the analytical stories based on CIS control 4, it shows me 6 stories all of which specifically address a certain use case. But I am having trouble understanding how a usecase is relevant to CIS 4 control. Take for e.g. Spectre And Meltdown Vulnerabilities maps to control 4. The only relevant sub-controls under 4 that can be detected using ES I found were: Log and Alert on Changes to Administrative Group Membership and Log and Alert on Unsuccessful Administrative Account Login. Can anyone please help understand how is the analytical story relevant to
... View more
Labels
01-09-2021
05:28 PM
We have a massive Splunk environment and QA process is pretty stringent when it comes to data onboarding. As part of that, we also do check the magix six props.conf attributes but process to check is time consuming. Hence, wondering what approach others here are taking to make the process fast and efficient. Any help on this would be highly appreciated. Thanks!
... View more
Labels
- Labels:
-
field extraction
-
inputs.conf
-
props.conf
01-06-2021
04:09 PM
But this is newly setup Splunk ES on Splunk Cloud. Could it be probably due to Indexes whitelist using all indexes in the "CIM setup" configuration of the ES app ?
... View more
01-05-2021
02:17 PM
Is SSL Certificate Checker supported or compatible with Splunk Cloud ?
... View more
01-04-2021
05:31 AM
Can anyone please share some best practise or your own preferred method for populating the watchlist field in the assets and identities lookup table in ES ? We are currently using Sailpoint data to populate the identities lookup. The only one reference i have got is someone using below logic by leveraging the ldapsearch command. | eval watchlist=if((userAccountControl % 4)>=2,"true","")
... View more
Labels
- Labels:
-
configuration
01-04-2021
05:01 AM
After accelerating the CIM Validation (S.o.S.) DM and upon checking the pivot for any of the datasets results in an error. Example below: Datamodel 'Splunk_CIM_Validation.Authentication' had an invalid search, cannot get indexes to search Upon checking the search.log, it states ERROR DataModelEvaluator [3485 BatchSearch] - Data model 'Authentication' was not found.
01-04-2021 12:56:11.393 ERROR SearchOperator:datamodel [3485 BatchSearch] - Error in 'DataModelEvaluator': Data model 'Authentication' was not found.
01-04-2021 12:56:11.394 ERROR TsidxStats [3485 BatchSearch] - Error in 'SearchOperator:datamodel': Error in 'DataModelEvaluator': Data model 'Authentication' was not found.
01-04-2021 12:56:11.394 ERROR TsidxStats [3485 BatchSearch] - sid:etc.splunkcloud.com Datamodel 'Splunk_CIM_Validation.Authentication' had an invalid search, cannot get indexes to search Update: I found some similar posts, where they mention this might be due to permission issue, but I have checked the permission for this DM and it is default to read for "Everyone". Other DMs with same permissions work well. Also, when acceleration is disabled, it seems shows data in pivot Can someone please help fix this ?
... View more
Labels
- Labels:
-
troubleshooting
12-17-2020
04:23 AM
I am too in exactly in need for some workaround for this issue. I cant use ldapsearch directly on ES cloud because of this.
... View more
- Tags:
- I am tooo
12-13-2020
09:53 PM
Pivot for Assets and Identities Data model -"Identity_Management" showing zero count. When running search - |tstats count from datamodel=Identity_Management by index Error in 'DataModelCache': Could not create search for invalid datamodel: Identity_Management
The search job has failed due to an error. You may be able view the job in the Job Inspector. 12-14-2020 05:50:01.195 ERROR DataModelCache [33401 searchOrchestrator] - Could not create search for invalid datamodel: Identity_Management
12-14-2020 05:50:01.195 ERROR SearchPhaseGenerator [33401 searchOrchestrator] - Fallback to two phase search failed:Error in 'DataModelCache': Could not create search for invalid datamodel: Identity_Management
12-14-2020 05:50:01.195 ERROR SearchOrchestrator [33401 searchOrchestrator] - Error in 'DataModelCache': Could not create search for invalid datamodel: Identity_Management
12-14-2020 05:50:01.195 ERROR SearchStatusEnforcer [33401 searchOrchestrator] - sid:1607925000.24084 Error in 'DataModelCache': Could not create search for invalid datamodel: Identity_Management Pleasse advise! Thanks!
... View more
Labels
- Labels:
-
administration
-
configuration
12-13-2020
02:05 AM
Thanks for your reply. Could you please give an example of hardcoding those fields in a script ?
... View more
12-10-2020
05:49 PM
Labels
- Labels:
-
configuration
12-10-2020
05:26 AM
Given these fields (is_expected, should_timesync, requires_av and should_update in asset lookup of ES) dont dynamically come from any data source, I am keen to know what methods people use to populate these fields in asset lookup ? Do you mainly create and maintain a static asset list for such fields ? Is there any better way or process to create and update this list ? Any help on this would be highly appreciated. Thanks
... View more
Labels
- Labels:
-
administration
12-08-2020
04:06 AM
Does ES also comes with SSE app features like Analytics Advisor, Content Recommendations, Data inventory, CIM compliance check etc ? I found these features really useful for data source assessment.
... View more
Labels
12-02-2020
03:34 AM
Labels
- Labels:
-
using Enterprise Security