<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk log4j in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-log4j/m-p/581747#M8776</link>
    <description>&lt;P&gt;Hello Splunkers,&lt;/P&gt;&lt;P&gt;I’ve created a search to show up all the log4j related events by looking into the strings. We are trying to dig into the events and schedule an alert.&lt;/P&gt;&lt;P&gt;Are there any particular messages we should check in the events for log4j vulnerability? Any particular events that has high risk factor?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;thanks in advance.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Jan 2022 21:11:41 GMT</pubDate>
    <dc:creator>revanthammineni</dc:creator>
    <dc:date>2022-01-19T21:11:41Z</dc:date>
    <item>
      <title>Splunk log4j</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-log4j/m-p/581747#M8776</link>
      <description>&lt;P&gt;Hello Splunkers,&lt;/P&gt;&lt;P&gt;I’ve created a search to show up all the log4j related events by looking into the strings. We are trying to dig into the events and schedule an alert.&lt;/P&gt;&lt;P&gt;Are there any particular messages we should check in the events for log4j vulnerability? Any particular events that has high risk factor?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;thanks in advance.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jan 2022 21:11:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-log4j/m-p/581747#M8776</guid>
      <dc:creator>revanthammineni</dc:creator>
      <dc:date>2022-01-19T21:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk log4j</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-log4j/m-p/581766#M8777</link>
      <description>There are examples and discussions on Splunk Slack on channel #log4jstuff.</description>
      <pubDate>Wed, 19 Jan 2022 22:03:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-log4j/m-p/581766#M8777</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-19T22:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk log4j</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-log4j/m-p/581785#M8778</link>
      <description>&lt;P&gt;Thanks for the quick response.&lt;BR /&gt;Could you send me the link to this channel. I couldn’t seem to find it.&lt;/P&gt;&lt;P&gt;Also, If you have any documents regards to my question, Please send them over. TIA&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jan 2022 23:04:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-log4j/m-p/581785#M8778</guid>
      <dc:creator>revanthammineni</dc:creator>
      <dc:date>2022-01-19T23:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk log4j</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-log4j/m-p/581834#M8779</link>
      <description>&lt;P&gt;Here is a link to Slack channel &lt;A href="https://splunk-usergroups.slack.com/archives/C02QJCLUFD4" target="_blank"&gt;https://splunk-usergroups.slack.com/archives/C02QJCLUFD4&lt;/A&gt;&lt;/P&gt;&lt;P&gt;And some other blogs / information about it&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://www.splunk.com/en_us/cyber-security/log4shell-log4j-response-overview.html" target="_blank"&gt;https://www.splunk.com/en_us/cyber-security/log4shell-log4j-response-overview.html&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.splunk.com/en_us/blog/bulletins/splunk-security-advisory-for-apache-log4j-cve-2021-44228.html" target="_blank"&gt;https://www.splunk.com/en_us/blog/bulletins/splunk-security-advisory-for-apache-log4j-cve-2021-44228.html&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.splunk.com/en_us/blog/security/log4shell-detecting-log4j-vulnerability-cve-2021-44228-continued.html" target="_blank"&gt;https://www.splunk.com/en_us/blog/security/log4shell-detecting-log4j-vulnerability-cve-2021-44228-continued.html&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.splunk.com/en_us/blog/security/log-jammin-log4j-2-rce.html" target="_blank"&gt;https://www.splunk.com/en_us/blog/security/log-jammin-log4j-2-rce.html&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jan 2022 06:40:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-log4j/m-p/581834#M8779</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-20T06:40:47Z</dc:date>
    </item>
  </channel>
</rss>

