<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Get logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Get-logs/m-p/693735#M115308</link>
    <description>&lt;P&gt;The way to get "data like bots dataset" would be to ingest it with a UF and then copy out buckets with indexed data.&lt;/P&gt;&lt;P&gt;Also remember that if an incident had already happened the attackers might have removed as many traces of their activity as they could. You can try to do some forensic analysis but that's not something Splunk is meant for. Yes, in a skilled person's hands it can be a tool helping in such analysis but it's not a forensic solution.&lt;/P&gt;</description>
    <pubDate>Thu, 18 Jul 2024 12:44:26 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2024-07-18T12:44:26Z</dc:date>
    <item>
      <title>Get logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Get-logs/m-p/693571#M115290</link>
      <description>&lt;P&gt;Hello everyone&lt;BR /&gt;I want help on how to deal with the following problem&lt;BR /&gt;A company that got hacked and we want to know how the hack happened and is there a data leak or not&lt;BR /&gt;The company does not use any of the EDR and sime and ndr systems&lt;BR /&gt;Question&lt;BR /&gt;The best way to extract logs from the company's systems and analyze them in splunk and what are the rules to start searching&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2024 06:00:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Get-logs/m-p/693571#M115290</guid>
      <dc:creator>tuts</dc:creator>
      <dc:date>2024-07-17T06:00:53Z</dc:date>
    </item>
    <item>
      <title>Re: Get logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Get-logs/m-p/693572#M115291</link>
      <description>&lt;P&gt;The best way of getting data from the company's systems is generally whatever is the easiest to get them out. Splunk can ingest data in many ways, but there are many standard ways of looking at data.&lt;/P&gt;&lt;P&gt;What systems do you have and what logs are available.&lt;/P&gt;&lt;P&gt;Do you currently use Splunk?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2024 06:10:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Get-logs/m-p/693572#M115291</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2024-07-17T06:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: Get logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Get-logs/m-p/693584#M115294</link>
      <description>&lt;P&gt;Yes, I'm currently working on Splunk.&lt;BR /&gt;I want to pull the data from Event Viewer and save them to the cvs file and then I add data for splunk is this the right way&lt;/P&gt;&lt;P&gt;I want the data to be understandable like botsv&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2024 07:39:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Get-logs/m-p/693584#M115294</guid>
      <dc:creator>tuts</dc:creator>
      <dc:date>2024-07-17T07:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: Get logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Get-logs/m-p/693645#M115302</link>
      <description>&lt;P&gt;The normal way to get data from windows machines is to install the universal forwarder on the machine and pretty much the rest happens as magic.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/blog/learn/splunk-universal-forwarder.html" target="_blank"&gt;https://www.splunk.com/en_us/blog/learn/splunk-universal-forwarder.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Also, you should install the TAs (Technical Add On) for Windows&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/742" target="_blank"&gt;https://splunkbase.splunk.com/app/742&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and then you will have the data in Splunk in a way that can be easily digested.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2024 22:32:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Get-logs/m-p/693645#M115302</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2024-07-17T22:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: Get logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Get-logs/m-p/693679#M115306</link>
      <description>&lt;P&gt;I don't want to use universal forwarder&lt;BR /&gt;I mean, what is the correct way to pull data from a hacked device, then take the data, save it in a folder, and then analyze it in splunk, and the hacked device does not have any universal forwarder and does not allow it to be installed&lt;BR /&gt;All I want is to know the way to create data from the device such as botsv2 data and analyze it in Splunk&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2024 07:24:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Get-logs/m-p/693679#M115306</guid>
      <dc:creator>tuts</dc:creator>
      <dc:date>2024-07-18T07:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: Get logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Get-logs/m-p/693735#M115308</link>
      <description>&lt;P&gt;The way to get "data like bots dataset" would be to ingest it with a UF and then copy out buckets with indexed data.&lt;/P&gt;&lt;P&gt;Also remember that if an incident had already happened the attackers might have removed as many traces of their activity as they could. You can try to do some forensic analysis but that's not something Splunk is meant for. Yes, in a skilled person's hands it can be a tool helping in such analysis but it's not a forensic solution.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2024 12:44:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Get-logs/m-p/693735#M115308</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-07-18T12:44:26Z</dc:date>
    </item>
  </channel>
</rss>

