<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Useful security searches in Security</title>
    <link>https://community.splunk.com/t5/Security/Useful-security-searches/m-p/43849#M1457</link>
    <description>&lt;P&gt;Too numerous to cover them all, but the things I have seen are:&lt;/P&gt;

&lt;P&gt;1) Using "transactions" to find abnormal behavior over a period of time (check out search reference guide to see what I mean).&lt;BR /&gt;
2) Finding correlations across multiple log files (my syslog says this, my checkpoint FW said that, and I got my IDS telling me this....so this is what is going on).&lt;BR /&gt;
3) Creating alerts and notifications that send emails or even log messages to your NOC.&lt;/P&gt;

&lt;P&gt;The key is to pump data into Splunk and let it "learn" what you put in there.  It will tell you things you never knew.&lt;/P&gt;</description>
    <pubDate>Sun, 25 Nov 2012 04:30:41 GMT</pubDate>
    <dc:creator>sd23c109</dc:creator>
    <dc:date>2012-11-25T04:30:41Z</dc:date>
    <item>
      <title>Useful security searches</title>
      <link>https://community.splunk.com/t5/Security/Useful-security-searches/m-p/43848#M1456</link>
      <description>&lt;P&gt;I am new to Splunk and am learning all about it, I was hoping you guys would be able to give me some examples of how I can use Splunk from a security prescriptive, I have already created searches for login failures but what else can Splunk do from a security point of view?&lt;/P&gt;

&lt;P&gt;Thanks,  &lt;/P&gt;</description>
      <pubDate>Fri, 23 Nov 2012 14:23:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Useful-security-searches/m-p/43848#M1456</guid>
      <dc:creator>robK123</dc:creator>
      <dc:date>2012-11-23T14:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: Useful security searches</title>
      <link>https://community.splunk.com/t5/Security/Useful-security-searches/m-p/43849#M1457</link>
      <description>&lt;P&gt;Too numerous to cover them all, but the things I have seen are:&lt;/P&gt;

&lt;P&gt;1) Using "transactions" to find abnormal behavior over a period of time (check out search reference guide to see what I mean).&lt;BR /&gt;
2) Finding correlations across multiple log files (my syslog says this, my checkpoint FW said that, and I got my IDS telling me this....so this is what is going on).&lt;BR /&gt;
3) Creating alerts and notifications that send emails or even log messages to your NOC.&lt;/P&gt;

&lt;P&gt;The key is to pump data into Splunk and let it "learn" what you put in there.  It will tell you things you never knew.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Nov 2012 04:30:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Useful-security-searches/m-p/43849#M1457</guid>
      <dc:creator>sd23c109</dc:creator>
      <dc:date>2012-11-25T04:30:41Z</dc:date>
    </item>
  </channel>
</rss>

