Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Splunk Enterprise Security Search

$
0
0
Dear Community, I have ES app in my environment & I have two requirements, 1. My `incident_review` macro is showing no result, though I have proper incident_review setting. 2. I want a search to get all the assets that were involved in all of the notable that occurred for a 30 day duration. Extremely Thankful to the community, you guys rock. Please let me know of the above requirements. Regards Prashant

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>