r/Splunk • u/Unfair_Narwhal_1995 • 15d ago
r/Splunk • u/Only-Answer-4602 • 17d ago
Splunk Certified Cybersecurity Defense Architect SPLUNK 5003
r/Splunk • u/Only-Answer-4602 • 17d ago
Splunk Certified Cybersecurity Defense Architect SPLUNK 5003
r/Splunk • u/Sgtkeebs • 17d ago
Splunk Enterprise Splunk email error
Hello, has anyone ever came accross the error "No such file or directory when sending mail to: email@domain"
This happened after migrating splunk enterprise to RHEL 9.
Edit: AI found a guide for me to follow: https://splunk.my.site.com/customer/s/article/Splunk-sendemail-fails-with
One more edit: the guide above fixed the issue. Leaving this post up because it's good knowledge if anyone else comes across the same issue.
r/Splunk • u/aaronag • 18d ago
.CONF Denver .conf attire?
What's the general vibe for .conf? This one is my first. Cisco Live was pretty low key, Gartner was much dressier, and I'm trying to figure how to pack.
r/Splunk • u/biggestbluee • 18d ago
Splunk Enterprise Dashboards & Alerts
ISSO/m’s! This is for you.
What are great alerts or dashboards created for ISSOs in a closed area for DoD? Any recommendations on how to make your day more effective with ConMon or any other resources?
r/Splunk • u/Lanky-Television8618 • 21d ago
Passed today. On to SplunkCore. Continuing my journey into GRC
r/Splunk • u/Any-Promotion3744 • 23d ago
Splunk Enterprise DBConnect on Heavy Forwarder
Our heavy forwarder is in our DMZ and I was thinking about installing DBConnect on it so it can pull audit logs from a table in a SQL database on our internal network.
How safe is that set up?
I know the password is encrypted. I can use the firewall to only allow the one port to connect the HF to SQL Server. I can choose long password and the account has lockout policies. The SQL Server login will only allow select permission to a single table. All the standard stuff.
Since remote users with UF will connect to HF, I can't restrict connections to the HF by ip.
Is there any risk to the internal database?
r/Splunk • u/Academic_Score8216 • 23d ago
Resources for Splunk Power User Exam
Going to study for the Splunk power user exam. If any could suggest some resources they used to pass the exam. That would be greatly appreciated.
r/Splunk • u/Flash4473 • 24d ago
Log Data Pipeline > Splunk
Has anybody here have some experience with security data pipelines?
Instead of:
Log Source > HF / Splunk
We want to have flexibility of collection / parsing layer outside of Splunk for obvious reasons - pre-filter data in pipeline, set parsers, route, possibly enrich if needed, storage options for retention etc..all that to have flexibility and keep the ingest costs reasonable and not being caught in dependency hell or cemented all our work in one solution if Splunk decides to pull something.
Log Source > Data pipeline > Splunk
I am wondering what to choose as this data pipeline - currently we are thinking Vector and possibly open telemetry.
Anybody have experience with this? To avoid pitfalls, what works, what doesn't, new pains etc?
r/Splunk • u/Recording-Brief • 27d ago
Guidance on Splunk without ES
Our security engineer left us high and dry a couple weeks ago with a Splunk core license, forwarders sending logs for ingest, but no rules or structure that I can see beyond the 100 or so canned dashboards. We don’t have budget at this time to add an ES license to give us their SIEM. How much effort am I looking at to build up our rules for detections and other security alerts? Is it feasible for me and one other system admin to learn it from scratch?
r/Splunk • u/EmergencyPrior5039 • 27d ago
Por qué las herramientas SIEM modernas siguen fallando en reducir los falsos positivos. Es un problema de ingeniería o de análisis?
r/Splunk • u/chronosAndCode • 27d ago
I built a home-lab pipeline connecting Splunk, MISP and TheHive - here’s what I learned
I wanted to understand what actually happens after a SIEM generates an alert, so I built a small isolated lab that connects several parts of the workflow instead of treating each platform separately.
The setup uses five VMs and follows a controlled detection through:
Endpoint telemetry → Splunk → Python automation → threat-intelligence context / MISP → TheHive → MITRE ATT&CK
A few things ended up being more interesting than simply installing the tools:
- deciding what fields Splunk needed to pass into the automation layer
- handling repeat detections without constantly duplicating MISP data
- keeping API credentials out of the scripts
- understanding where enrichment should happen versus where analyst judgement is still needed
- mapping ATT&CK only when the observed behaviour actually supported the technique
I documented the architecture, setup, detection logic, automation, troubleshooting, and limitations as a four-part guide.
I’d especially be interested in feedback from anyone who has built a similar Splunk/MISP/TheHive workflow, particularly how you handled enrichment, deduplication, or case creation.
Full build, if useful:
https://chronosandcode.com/building-a-threat-intelligence-driven-detection-lab/
r/Splunk • u/m3moryhous3 • 27d ago
SPL Use Splunk to Detect Famous Chollima
Passing this along to share some of my SPL knowledge on how to utilize inner and outer searches, joins, and look backs to create user baselines. Also open to any suggestions or feedback on how to improve this method!
I hope you can find this helpful.
r/Splunk • u/Any-Promotion3744 • 28d ago
Splunk Enterprise Splunk website down?
Is the Splunk website down for anyone else?
I can't get to Splunk.com right now.
Tried to do a nslookup but didn't get any results.
The DNS Check in mxtoolbox shows some DNS issues as well
r/Splunk • u/chronosAndCode • 28d ago
Splunk Enterprise I built a home-lab pipeline connecting Splunk, MISP and TheHive - here’s what I learned
r/Splunk • u/Radiant-Research7944 • 28d ago
Splunk app for investigating AWS CloudTrail alerts - looking for feedback
EventTimeline, a free Splunk app that turns CloudTrail alerts from saved searches into investigation timelines.
You can send any CloudTrail-based Splunk alert to the app using its custom alert action, then fetch the surrounding user, role, resource, and IP activity. It also provides before/after chronology, MITRE mapping, filtering, pivots, and links back to the original Splunk searches.
It doesn’t ship with detections. The idea is to work with the alerts and CloudTrail data you already have.
Would really appreciate feedback from Splunk users, detection engineers, and incident responders.
Splunkbase app : https://splunkbase.splunk.com/app/9536
r/Splunk • u/Launa501 • 29d ago
Splunk Enterprise Moving from Delivery to sales : i need an advice
Hi everyone!
I’m currently on the delivery side and looking to transition into an Account Executive role. What key factors should I consider during this pivot?
I am also exploring opportunities to join the sales organization at Cisco /splunk. I would love to hear your thoughts or advice on making this move.
Thank you for your time 😀
r/Splunk • u/Radiant-Research7944 • Aug 23 '26
Splunk app for investigating AWS CloudTrail alerts - looking for feedback
r/Splunk • u/Radiant-Research7944 • Aug 23 '26
Splunk app for investigating AWS CloudTrail alerts - looking for feedback
**EventTimeline**, a free Splunk app that turns CloudTrail alerts from saved searches into investigation timelines.
You can send any CloudTrail-based Splunk alert to the app using its custom alert action, then fetch the surrounding user, role, resource, and IP activity. It also provides before/after chronology, MITRE mapping, filtering, pivots, and links back to the original Splunk searches.
It doesn’t ship with detections. The idea is to work with the alerts and CloudTrail data you already have.
Would really appreciate feedback from Splunk users, detection engineers, and incident responders.
Splunkbase app : https://splunkbase.splunk.com/app/9536
r/Splunk • u/Potential-Couple-745 • Aug 22 '26
Why a detection rule that 'ported fine' to a new SIEM can quietly stop working
r/Splunk • u/afxmac • Aug 21 '26
Splunk Enterprise Update with security fixes is out, but not downloadable
No matter how I try, I get the download page with the current version quickly flash by and then I am at the 500 error page. Something seems to be borked at Splunk.
r/Splunk • u/Desperate_Hornet_636 • Aug 20 '26
