<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Queries for multiple tasks in Security</title>
    <link>https://community.splunk.com/t5/Security/Help-with-Search-for-multiple-tasks/m-p/628302#M16551</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253226"&gt;@Cyberguru&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;there isn't a general answer to your question because the searches depend on the data you have: e.g. if you speak of malicious host, this depends on the Antivirus or WAF or the IPS/IDS you're using.&lt;/P&gt;&lt;P&gt;So start from the technologies you're collecting logs, then see in Splunkbase (apps.splunk.com) if there's an App (usually there is!) that gives you the dashboards you need.&lt;/P&gt;&lt;P&gt;In addition I hint to install and see the Splunk Security Essentials App (&lt;A href="https://splunkbase.splunk.com/app/3435)" target="_blank"&gt;https://splunkbase.splunk.com/app/3435)&lt;/A&gt;&amp;nbsp;that contains many security searches and guides you in the data analysis.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Wed, 25 Jan 2023 15:59:38 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-01-25T15:59:38Z</dc:date>
    <item>
      <title>Help with Search for multiple tasks</title>
      <link>https://community.splunk.com/t5/Security/Help-with-Search-for-multiple-tasks/m-p/628297#M16550</link>
      <description>&lt;P&gt;Hey Splunk Community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Working on a dashboard ( For Incident Response) in splunk but need some assistance initially with queries on the following in Splunk:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Computer or host showing if malicious&lt;/LI&gt;
&lt;LI&gt;Logon info for other machines that a user has logged in for the ay&lt;/LI&gt;
&lt;LI&gt;IP address of machine, Location or Country, Is it a VM, and Laptop&lt;/LI&gt;
&lt;LI&gt;Active Directory info on user&lt;/LI&gt;
&lt;LI&gt;Remote machine name - to find out what machine was used to remote into the Server on the last incident&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Need this soon, would be appreciated.&lt;/P&gt;
&lt;P&gt;Thanks Very much!&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 00:02:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Help-with-Search-for-multiple-tasks/m-p/628297#M16550</guid>
      <dc:creator>Cyberguru</dc:creator>
      <dc:date>2023-01-26T00:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: Queries for multiple tasks</title>
      <link>https://community.splunk.com/t5/Security/Help-with-Search-for-multiple-tasks/m-p/628302#M16551</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253226"&gt;@Cyberguru&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;there isn't a general answer to your question because the searches depend on the data you have: e.g. if you speak of malicious host, this depends on the Antivirus or WAF or the IPS/IDS you're using.&lt;/P&gt;&lt;P&gt;So start from the technologies you're collecting logs, then see in Splunkbase (apps.splunk.com) if there's an App (usually there is!) that gives you the dashboards you need.&lt;/P&gt;&lt;P&gt;In addition I hint to install and see the Splunk Security Essentials App (&lt;A href="https://splunkbase.splunk.com/app/3435)" target="_blank"&gt;https://splunkbase.splunk.com/app/3435)&lt;/A&gt;&amp;nbsp;that contains many security searches and guides you in the data analysis.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 15:59:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Help-with-Search-for-multiple-tasks/m-p/628302#M16551</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-01-25T15:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: Queries for multiple tasks</title>
      <link>https://community.splunk.com/t5/Security/Help-with-Search-for-multiple-tasks/m-p/628304#M16552</link>
      <description>&lt;P&gt;Just need -malicious host for Symantec AV for e.g.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 16:03:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Help-with-Search-for-multiple-tasks/m-p/628304#M16552</guid>
      <dc:creator>Cyberguru</dc:creator>
      <dc:date>2023-01-25T16:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: Queries for multiple tasks</title>
      <link>https://community.splunk.com/t5/Security/Help-with-Search-for-multiple-tasks/m-p/628307#M16553</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253226"&gt;@Cyberguru&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;see in Splunkbase (apps.splunk.com) the Add-on to collect data and the App to display data.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 16:09:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Help-with-Search-for-multiple-tasks/m-p/628307#M16553</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-01-25T16:09:34Z</dc:date>
    </item>
  </channel>
</rss>

