<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to see result from CMD in Splunk ? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-result-from-CMD-in-Splunk/m-p/707520#M28961</link>
    <description>&lt;P&gt;I give you karma for this, i forget my client using Palo Alto to detect it.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Dec 2024 04:30:21 GMT</pubDate>
    <dc:creator>zksvc</dc:creator>
    <dc:date>2024-12-24T04:30:21Z</dc:date>
    <item>
      <title>How to see result from CMD in Splunk ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-result-from-CMD-in-Splunk/m-p/707258#M28953</link>
      <description>&lt;P&gt;Hi Everyone,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was create my own lab for learning to configure best practice for Windows.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then i create 1 Windows VM and doing scan in local (127.0.0.1) to get any information like port or something else. But unfortunately when it trigger i can't see anything like the result.&lt;/P&gt;&lt;P&gt;Maybe i need to config something in my Windows or Something ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 08:19:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-result-from-CMD-in-Splunk/m-p/707258#M28953</guid>
      <dc:creator>zksvc</dc:creator>
      <dc:date>2024-12-19T08:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to see result from CMD in Splunk ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-result-from-CMD-in-Splunk/m-p/707259#M28954</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/269896"&gt;@zksvc&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you have to follow the instructions at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.3.2/Forwarding/Aboutforwardingandreceivingdata" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.3.2/Forwarding/Aboutforwardingandreceivingdata&lt;/A&gt;&amp;nbsp;or&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.3.2/Forwarding/Aboutforwardingandreceivingdata" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.3.2/Forwarding/Aboutforwardingandreceivingdata&lt;/A&gt;&lt;/P&gt;&lt;P&gt;there are also many videos to explain this.&lt;/P&gt;&lt;P&gt;in few words:&lt;/P&gt;&lt;P&gt;enable Splunk to receive logs,&lt;/P&gt;&lt;P&gt;install Unioversal Forwarder on the windows system&lt;/P&gt;&lt;P&gt;install Splunk_TA_Windows on the Universal Forwarder&lt;/P&gt;&lt;P&gt;enable inputs on the Splunk_TA_Windows&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 08:38:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-result-from-CMD-in-Splunk/m-p/707259#M28954</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-12-19T08:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to see result from CMD in Splunk ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-result-from-CMD-in-Splunk/m-p/707265#M28955</link>
      <description>&lt;P&gt;What exactly are you trying to achieve and how are you doing that?&lt;/P&gt;&lt;P&gt;What you've shown is an event from Windows Security eventlog which is apparently an audit entry informing you that a process has been spawned on a machine. As far as I remember it doesn't capture command's output.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 10:21:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-result-from-CMD-in-Splunk/m-p/707265#M28955</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-12-19T10:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to see result from CMD in Splunk ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-result-from-CMD-in-Splunk/m-p/707354#M28958</link>
      <description>&lt;P&gt;Hmm so if one of endpoint got hacked and someone doing running script we cannot collect information from output in cmd/powershell ?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 06:23:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-result-from-CMD-in-Splunk/m-p/707354#M28958</guid>
      <dc:creator>zksvc</dc:creator>
      <dc:date>2024-12-20T06:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to see result from CMD in Splunk ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-result-from-CMD-in-Splunk/m-p/707355#M28959</link>
      <description>&lt;P&gt;Already install TA - Windows and restart in UF also installed it in Indexer but why i still cannot read the output ? did i forget to setting something ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 06:29:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-result-from-CMD-in-Splunk/m-p/707355#M28959</guid>
      <dc:creator>zksvc</dc:creator>
      <dc:date>2024-12-20T06:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to see result from CMD in Splunk ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-result-from-CMD-in-Splunk/m-p/707356#M28960</link>
      <description>&lt;P&gt;I'm not aware of any built-in mechanism that allows you to do so. Maybe some external EDR solution captures that but I can't advise any.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 10:39:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-result-from-CMD-in-Splunk/m-p/707356#M28960</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-12-20T10:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to see result from CMD in Splunk ?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-result-from-CMD-in-Splunk/m-p/707520#M28961</link>
      <description>&lt;P&gt;I give you karma for this, i forget my client using Palo Alto to detect it.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2024 04:30:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-see-result-from-CMD-in-Splunk/m-p/707520#M28961</guid>
      <dc:creator>zksvc</dc:creator>
      <dc:date>2024-12-24T04:30:21Z</dc:date>
    </item>
  </channel>
</rss>

