<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: advhunt custom Command in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/advhunt-custom-Command/m-p/712028#M12366</link>
    <description>&lt;P&gt;I think this "admin_all_objects" privilege is needed by the app to access the client secret stored in the app, which is used to authenticate the advanced hunting requests.&lt;/P&gt;&lt;P&gt;There is another app (&lt;A href="https://splunkbase.splunk.com/app/6463" target="_blank"&gt;https://splunkbase.splunk.com/app/6463&lt;/A&gt;) which appears to do the same thing albeit with a differently named command "defkqlg". It says in the Details tab that you can use the "edit_storage_passwords" capability instead of "admin_all_objects" if your Splunk Enterprise version is later than 9.1.0.&lt;/P&gt;&lt;P&gt;It might also be possible to use edit_storage_passwords privilege instead on the MS Defender Advanced Hunting app, but it would need to be tested.&lt;/P&gt;</description>
    <pubDate>Wed, 19 Feb 2025 19:15:07 GMT</pubDate>
    <dc:creator>marnall</dc:creator>
    <dc:date>2025-02-19T19:15:07Z</dc:date>
    <item>
      <title>advhunt custom Command</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/advhunt-custom-Command/m-p/712026#M12365</link>
      <description>&lt;P&gt;Our Security partners at work recently determined that their analyst need the ability to run the custom command:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;advhunt (&lt;SPAN&gt;TA_ms_advanced_hunting)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;The custom command indicates:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;To use this app, users need following privileges.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;list_storage_passwords&lt;/LI&gt;&lt;LI&gt;admin_all_objects&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;We do not want to give all Security users the ability to admin_all_objects. What other options do we have?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2025 18:37:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/advhunt-custom-Command/m-p/712026#M12365</guid>
      <dc:creator>Morty2</dc:creator>
      <dc:date>2025-02-19T18:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: advhunt custom Command</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/advhunt-custom-Command/m-p/712028#M12366</link>
      <description>&lt;P&gt;I think this "admin_all_objects" privilege is needed by the app to access the client secret stored in the app, which is used to authenticate the advanced hunting requests.&lt;/P&gt;&lt;P&gt;There is another app (&lt;A href="https://splunkbase.splunk.com/app/6463" target="_blank"&gt;https://splunkbase.splunk.com/app/6463&lt;/A&gt;) which appears to do the same thing albeit with a differently named command "defkqlg". It says in the Details tab that you can use the "edit_storage_passwords" capability instead of "admin_all_objects" if your Splunk Enterprise version is later than 9.1.0.&lt;/P&gt;&lt;P&gt;It might also be possible to use edit_storage_passwords privilege instead on the MS Defender Advanced Hunting app, but it would need to be tested.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2025 19:15:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/advhunt-custom-Command/m-p/712028#M12366</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2025-02-19T19:15:07Z</dc:date>
    </item>
  </channel>
</rss>

