<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Detect Web Application Attacks using Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-Detect-Web-Application-Attacks-using-Splunk/m-p/261093#M50082</link>
    <description>&lt;P&gt;Does anybody know the price for this app?&lt;/P&gt;</description>
    <pubDate>Tue, 06 Dec 2016 11:28:21 GMT</pubDate>
    <dc:creator>kairobin</dc:creator>
    <dc:date>2016-12-06T11:28:21Z</dc:date>
    <item>
      <title>How to Detect Web Application Attacks using Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-Detect-Web-Application-Attacks-using-Splunk/m-p/261090#M50079</link>
      <description>&lt;P&gt;Dear Splunkers!&lt;/P&gt;

&lt;P&gt;We have set up our Splunk environment to monitor all webserver logs in our DMZ. There are several windows IIS webservers and some apache and nginx servers in our environment. &lt;/P&gt;

&lt;P&gt;Now we are facing the challenge of making use of the dozens of logs we are collecting from those webservers. Basically, we aim to detect attack patterns of any possible web application attack. We already implemented some searches detecting injection and xss attacks using regexes for filtering relevant strings in the logfiles. This works quite OK, but doesn't seem to be very efficient performance-wise.&lt;/P&gt;

&lt;P&gt;Is there any recommendation on how to ideally use Splunk for web application/webserver log monitoring? Does someone have any hints for tutorials, best practices or whatever? Since this is of course a significant amount of know-how that is needed, we are not expecting to get all the necessary information for free - but we would be very thankful on hints where we could possibly get the necessary know how.&lt;/P&gt;

&lt;P&gt;yours,&lt;BR /&gt;
brian799&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 11:40:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-Detect-Web-Application-Attacks-using-Splunk/m-p/261090#M50079</guid>
      <dc:creator>brian_799</dc:creator>
      <dc:date>2015-12-03T11:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to Detect Web Application Attacks using Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-Detect-Web-Application-Attacks-using-Splunk/m-p/261091#M50080</link>
      <description>&lt;P&gt;There's an app for that &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/263/"&gt;https://splunkbase.splunk.com/app/263/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 16:13:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-Detect-Web-Application-Attacks-using-Splunk/m-p/261091#M50080</guid>
      <dc:creator>sundareshr</dc:creator>
      <dc:date>2015-12-03T16:13:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to Detect Web Application Attacks using Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-Detect-Web-Application-Attacks-using-Splunk/m-p/261092#M50081</link>
      <description>&lt;P&gt;Does the current version actually provide the necessary searches, etc. to reliably detect web application attacks? We evaluated the ES app a few years ago and were not entirely convinced by the functionality it provided - that was of course an older version.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 15:07:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-Detect-Web-Application-Attacks-using-Splunk/m-p/261092#M50081</guid>
      <dc:creator>brian_799</dc:creator>
      <dc:date>2015-12-04T15:07:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to Detect Web Application Attacks using Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-Detect-Web-Application-Attacks-using-Splunk/m-p/261093#M50082</link>
      <description>&lt;P&gt;Does anybody know the price for this app?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 11:28:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-Detect-Web-Application-Attacks-using-Splunk/m-p/261093#M50082</guid>
      <dc:creator>kairobin</dc:creator>
      <dc:date>2016-12-06T11:28:21Z</dc:date>
    </item>
  </channel>
</rss>

