<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: overall security dashboard in Security</title>
    <link>https://community.splunk.com/t5/Security/overall-security-dashboard/m-p/135342#M4140</link>
    <description>&lt;P&gt;First, you should use eventtypes for failed login (windows and Unix apps should do that for your) and try to normalize your data (see the CIM standard). This will help you to simplify your queries, make them faster using the datamodel, and when you need a more advanced security solution, will simplify your migration to Enterprise Security.&lt;/P&gt;</description>
    <pubDate>Wed, 31 Dec 2014 15:19:48 GMT</pubDate>
    <dc:creator>mdessus_splunk</dc:creator>
    <dc:date>2014-12-31T15:19:48Z</dc:date>
    <item>
      <title>overall security dashboard</title>
      <link>https://community.splunk.com/t5/Security/overall-security-dashboard/m-p/135338#M4136</link>
      <description>&lt;P&gt;trying to make a dashboard for overall security in splunk.&lt;BR /&gt;
here is a few of the searches i have:&lt;BR /&gt;
Webattacks - index=main "../etc/passwd" OR "union select" OR "javascript:" OR "&lt;SCRIPT&gt;&amp;amp;quot; query!=&amp;amp;quot;getHelp()&amp;amp;quot; | stats count by host&amp;lt;/p&amp;gt;

&amp;lt;p&amp;gt;failed logins - index=main &amp;amp;quot;EventCode=4776&amp;amp;quot; OR &amp;amp;quot;Failed password for&amp;amp;quot; OR &amp;amp;quot;Access denied for user&amp;amp;quot; OR &amp;amp;quot;Login failed for user&amp;amp;quot; | stats count by host | search count &amp;amp;gt; 3 | sort by count&amp;lt;/p&amp;gt;

&amp;lt;p&amp;gt;the failed logins is to detect windows logins, ssh, mysql, and mssql&amp;lt;/p&amp;gt;

&amp;lt;p&amp;gt;anyone have any suggestion on improving them?&amp;lt;/p&amp;gt;

&amp;lt;p&amp;gt;i have also been trying to build searches to detect APTs, maleware, and network attacks like dns and arp spoofing/poisoning. Any pointers on that? thank you.&amp;lt;/p&amp;gt;&lt;/SCRIPT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2014 17:33:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/overall-security-dashboard/m-p/135338#M4136</guid>
      <dc:creator>emada</dc:creator>
      <dc:date>2014-04-17T17:33:47Z</dc:date>
    </item>
    <item>
      <title>Re: overall security dashboard</title>
      <link>https://community.splunk.com/t5/Security/overall-security-dashboard/m-p/135339#M4137</link>
      <description>&lt;P&gt;You should take a look at the Enterprise Security app: &lt;A href="http://apps.splunk.com/app/263/"&gt;http://apps.splunk.com/app/263/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2014 18:28:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/overall-security-dashboard/m-p/135339#M4137</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-04-17T18:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: overall security dashboard</title>
      <link>https://community.splunk.com/t5/Security/overall-security-dashboard/m-p/135340#M4138</link>
      <description>&lt;P&gt;do you happen to know where to find the queries its using?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2014 20:20:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/overall-security-dashboard/m-p/135340#M4138</guid>
      <dc:creator>emada</dc:creator>
      <dc:date>2014-04-17T20:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: overall security dashboard</title>
      <link>https://community.splunk.com/t5/Security/overall-security-dashboard/m-p/135341#M4139</link>
      <description>&lt;P&gt;They're stored within the app configuration, just like with any other app.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2014 20:22:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/overall-security-dashboard/m-p/135341#M4139</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-04-17T20:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: overall security dashboard</title>
      <link>https://community.splunk.com/t5/Security/overall-security-dashboard/m-p/135342#M4140</link>
      <description>&lt;P&gt;First, you should use eventtypes for failed login (windows and Unix apps should do that for your) and try to normalize your data (see the CIM standard). This will help you to simplify your queries, make them faster using the datamodel, and when you need a more advanced security solution, will simplify your migration to Enterprise Security.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Dec 2014 15:19:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/overall-security-dashboard/m-p/135342#M4140</guid>
      <dc:creator>mdessus_splunk</dc:creator>
      <dc:date>2014-12-31T15:19:48Z</dc:date>
    </item>
  </channel>
</rss>

