<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using Splunk to replace manual viewing of security logs in Security</title>
    <link>https://community.splunk.com/t5/Security/Using-Splunk-to-replace-manual-viewing-of-security-logs/m-p/71691#M2371</link>
    <description>&lt;P&gt;It's only available for purchase to Enterprise customers, so you'd have to upgrade your splunk license as well. That's a good idea either way though &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Critically, you cannot define alerts in the free version.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Mar 2013 16:29:18 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2013-03-22T16:29:18Z</dc:date>
    <item>
      <title>Using Splunk to replace manual viewing of security logs</title>
      <link>https://community.splunk.com/t5/Security/Using-Splunk-to-replace-manual-viewing-of-security-logs/m-p/71687#M2367</link>
      <description>&lt;P&gt;Good Morning-&lt;/P&gt;

&lt;P&gt;We currently have Splunk installed in house but not overly configured.  Each week, I take a our security logs using the MS dumpel command, and compile the 92 logs into one 2 GB text file, run that through a MS Access Database, to kick out a series of critical event logs to review as part of the company I work for's company information security policy and practice of which we have to report to the SEC for Sarbanes-Oxley compliancy.  I'm hoping to be able to set up alerts in Splunk to email if certain criteria are found and kick those alerts into our Sharepoint environment to act as a log for this instead.  Any advice on configuring alerts like this would be greatly appreciated.&lt;/P&gt;

&lt;P&gt;Thanks-&lt;/P&gt;

&lt;P&gt;--Ryan&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2013 14:14:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Using-Splunk-to-replace-manual-viewing-of-security-logs/m-p/71687#M2367</guid>
      <dc:creator>ryjones13</dc:creator>
      <dc:date>2013-03-22T14:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk to replace manual viewing of security logs</title>
      <link>https://community.splunk.com/t5/Security/Using-Splunk-to-replace-manual-viewing-of-security-logs/m-p/71688#M2368</link>
      <description>&lt;P&gt;That sounds a lot like a use case for the &lt;A href="http://splunk-base.splunk.com/apps/22297/splunk-app-for-enterprise-security"&gt;http://splunk-base.splunk.com/apps/22297/splunk-app-for-enterprise-security&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You can define additional criteria to match your specific requirements to automatically have Splunk generate events for your team to review.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2013 15:06:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Using-Splunk-to-replace-manual-viewing-of-security-logs/m-p/71688#M2368</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-03-22T15:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk to replace manual viewing of security logs</title>
      <link>https://community.splunk.com/t5/Security/Using-Splunk-to-replace-manual-viewing-of-security-logs/m-p/71689#M2369</link>
      <description>&lt;P&gt;That looks like it would work but we use the free version, not the Enterprise one.  Can I pay for just this app?  Or are there notices I can configure within the system?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2013 16:09:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Using-Splunk-to-replace-manual-viewing-of-security-logs/m-p/71689#M2369</guid>
      <dc:creator>ryjones13</dc:creator>
      <dc:date>2013-03-22T16:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk to replace manual viewing of security logs</title>
      <link>https://community.splunk.com/t5/Security/Using-Splunk-to-replace-manual-viewing-of-security-logs/m-p/71690#M2370</link>
      <description>&lt;P&gt;Hello Ryan,&lt;/P&gt;

&lt;P&gt;if i did understand your archtiecture correctly i would suggest you to send all MS Events into Splunk... from there you can classify them with tags or extract some fields and create reports + alerts. &lt;/P&gt;

&lt;P&gt;then you can decide if you want to have a report which is sent as PDF regulary to a mailbox which stores it on a sharepoint or you can use alerts who trigger a command. via the command you can give also parameters and trigger a script what might generate something on your sharepoint... &lt;/P&gt;

&lt;P&gt;maybe if you have something with access databases and you want to keep those, have a look to the DB Connect App which can pull and push information via JDBC.&lt;/P&gt;

&lt;P&gt;br&lt;BR /&gt;
matthias&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2013 16:15:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Using-Splunk-to-replace-manual-viewing-of-security-logs/m-p/71690#M2370</guid>
      <dc:creator>Matthias_BY</dc:creator>
      <dc:date>2013-03-22T16:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk to replace manual viewing of security logs</title>
      <link>https://community.splunk.com/t5/Security/Using-Splunk-to-replace-manual-viewing-of-security-logs/m-p/71691#M2371</link>
      <description>&lt;P&gt;It's only available for purchase to Enterprise customers, so you'd have to upgrade your splunk license as well. That's a good idea either way though &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Critically, you cannot define alerts in the free version.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2013 16:29:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Using-Splunk-to-replace-manual-viewing-of-security-logs/m-p/71691#M2371</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-03-22T16:29:18Z</dc:date>
    </item>
  </channel>
</rss>

