<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how do I make splunk es to check my uploaded logs in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/how-do-I-make-splunk-es-to-check-my-uploaded-logs/m-p/689731#M11998</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/268709"&gt;@testttt&lt;/a&gt;&amp;nbsp;There&amp;nbsp;are&amp;nbsp;no&amp;nbsp;notable&amp;nbsp;events&amp;nbsp;that&amp;nbsp;you&amp;nbsp;can&amp;nbsp;produce&amp;nbsp;because&amp;nbsp;you&amp;nbsp;have&amp;nbsp;uploaded&amp;nbsp;sample&amp;nbsp;events&amp;nbsp;to&amp;nbsp;Splunk.&amp;nbsp;Could&amp;nbsp;you&amp;nbsp;please&amp;nbsp;create&amp;nbsp;an&amp;nbsp;instance,&amp;nbsp;send&amp;nbsp;the&amp;nbsp;logs&amp;nbsp;to&amp;nbsp;Splunk,&amp;nbsp;and&amp;nbsp;attempt&amp;nbsp;to&amp;nbsp;produce&amp;nbsp;the&amp;nbsp;notable&amp;nbsp;events? such&amp;nbsp;as&amp;nbsp;unsuccessful&amp;nbsp;login&amp;nbsp;attempts&amp;nbsp;and&amp;nbsp;bruteforce&amp;nbsp;attacks.&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jun 2024 16:32:29 GMT</pubDate>
    <dc:creator>kiran_panchavat</dc:creator>
    <dc:date>2024-06-05T16:32:29Z</dc:date>
    <item>
      <title>how do I make splunk es to check my uploaded logs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/how-do-I-make-splunk-es-to-check-my-uploaded-logs/m-p/689688#M11997</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I have installed splunk es app and uploaded botsv1.stream_http.json (&lt;A href="https://github.com/splunk/attack_data" target="_blank"&gt;https://github.com/splunk/attack_data&lt;/A&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="336788958-05898aa7-26ac-4db7-ac9f-9cc72fb6feb2.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31156i4B1E6EC4AE26799B/image-size/large?v=v2&amp;amp;px=999" role="button" title="336788958-05898aa7-26ac-4db7-ac9f-9cc72fb6feb2.png" alt="336788958-05898aa7-26ac-4db7-ac9f-9cc72fb6feb2.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;SPAN&gt;but incident_review and ess_security_posture is not hitting any event&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="336789872-68990f35-2468-4ef5-82e8-1da409d20585.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31155i9013FBAB35965A7A/image-size/large?v=v2&amp;amp;px=999" role="button" title="336789872-68990f35-2468-4ef5-82e8-1da409d20585.png" alt="336789872-68990f35-2468-4ef5-82e8-1da409d20585.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;how do I make splunk es to check my uploaded logs and generate a list of alerts like below. Please note that I am not checking the logs forwarded by agent, but the log files uploaded on the browser side&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="336793300-1a8315ea-8ac6-47e2-98d2-eaf79ce0391d.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31157i1BA851B8F6FC8ED6/image-size/large?v=v2&amp;amp;px=999" role="button" title="336793300-1a8315ea-8ac6-47e2-98d2-eaf79ce0391d.png" alt="336793300-1a8315ea-8ac6-47e2-98d2-eaf79ce0391d.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;thank you&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 11:09:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/how-do-I-make-splunk-es-to-check-my-uploaded-logs/m-p/689688#M11997</guid>
      <dc:creator>testttt</dc:creator>
      <dc:date>2024-06-05T11:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: how do I make splunk es to check my uploaded logs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/how-do-I-make-splunk-es-to-check-my-uploaded-logs/m-p/689731#M11998</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/268709"&gt;@testttt&lt;/a&gt;&amp;nbsp;There&amp;nbsp;are&amp;nbsp;no&amp;nbsp;notable&amp;nbsp;events&amp;nbsp;that&amp;nbsp;you&amp;nbsp;can&amp;nbsp;produce&amp;nbsp;because&amp;nbsp;you&amp;nbsp;have&amp;nbsp;uploaded&amp;nbsp;sample&amp;nbsp;events&amp;nbsp;to&amp;nbsp;Splunk.&amp;nbsp;Could&amp;nbsp;you&amp;nbsp;please&amp;nbsp;create&amp;nbsp;an&amp;nbsp;instance,&amp;nbsp;send&amp;nbsp;the&amp;nbsp;logs&amp;nbsp;to&amp;nbsp;Splunk,&amp;nbsp;and&amp;nbsp;attempt&amp;nbsp;to&amp;nbsp;produce&amp;nbsp;the&amp;nbsp;notable&amp;nbsp;events? such&amp;nbsp;as&amp;nbsp;unsuccessful&amp;nbsp;login&amp;nbsp;attempts&amp;nbsp;and&amp;nbsp;bruteforce&amp;nbsp;attacks.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 16:32:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/how-do-I-make-splunk-es-to-check-my-uploaded-logs/m-p/689731#M11998</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2024-06-05T16:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: how do I make splunk es to check my uploaded logs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/how-do-I-make-splunk-es-to-check-my-uploaded-logs/m-p/689819#M12000</link>
      <description>&lt;P&gt;I created a dvwa application and used SplunkUniversalForwarder to forward the log to port 9997, containing events such as sql injection and brute force cracking,&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="微信截图_20240606163504.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31187iA90D026552567841/image-size/large?v=v2&amp;amp;px=999" role="button" title="微信截图_20240606163504.png" alt="微信截图_20240606163504.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="微信截图_20240606163352.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31188i748E16F72C277673/image-size/large?v=v2&amp;amp;px=999" role="button" title="微信截图_20240606163352.png" alt="微信截图_20240606163352.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;but incident_review and ess_security_posture is not hitting any event&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="微信截图_20240606163605.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31186i6F486FB1B9FCA07B/image-size/large?v=v2&amp;amp;px=999" role="button" title="微信截图_20240606163605.png" alt="微信截图_20240606163605.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2024 09:00:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/how-do-I-make-splunk-es-to-check-my-uploaded-logs/m-p/689819#M12000</guid>
      <dc:creator>testttt</dc:creator>
      <dc:date>2024-06-06T09:00:27Z</dc:date>
    </item>
  </channel>
</rss>

