<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Enterprise Security: Is it possible to create a correlation search on admin activity and if yes, what data model is suitable for it? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-create-a/m-p/259095#M1900</link>
    <description>&lt;P&gt;i want  to see an event in incident review on admin activity, how to create a correlation search for, give me advice guys this is high priority. &lt;/P&gt;</description>
    <pubDate>Tue, 24 Jan 2017 22:18:35 GMT</pubDate>
    <dc:creator>Rocky31</dc:creator>
    <dc:date>2017-01-24T22:18:35Z</dc:date>
    <item>
      <title>Splunk Enterprise Security: Is it possible to create a correlation search on admin activity and if yes, what data model is suitable for it?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-create-a/m-p/259095#M1900</link>
      <description>&lt;P&gt;i want  to see an event in incident review on admin activity, how to create a correlation search for, give me advice guys this is high priority. &lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2017 22:18:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-create-a/m-p/259095#M1900</guid>
      <dc:creator>Rocky31</dc:creator>
      <dc:date>2017-01-24T22:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Is it possible to create a correlation search on admin activity and if yes, what data model is suitable for it?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-create-a/m-p/259096#M1901</link>
      <description>&lt;P&gt;You can create correlation search as per your requirement, however there aren't any data models which you can use for this.  For admin activities you should be able to get data from _internal index.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 09:33:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-create-a/m-p/259096#M1901</guid>
      <dc:creator>hardikJsheth</dc:creator>
      <dc:date>2017-01-25T09:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Is it possible to create a correlation search on admin activity and if yes, what data model is suitable for it?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-create-a/m-p/259097#M1902</link>
      <description>&lt;P&gt;Thanks for  your reply. i don't see any internal index, you mean internal_audit_logs,  splunk_audit. &lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:35:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-create-a/m-p/259097#M1902</guid>
      <dc:creator>Rocky31</dc:creator>
      <dc:date>2020-09-29T12:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Is it possible to create a correlation search on admin activity and if yes, what data model is suitable for it?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-create-a/m-p/259098#M1903</link>
      <description>&lt;P&gt;i mean what is best suitable application context.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 14:41:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-create-a/m-p/259098#M1903</guid>
      <dc:creator>Rocky31</dc:creator>
      <dc:date>2017-01-25T14:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Is it possible to create a correlation search on admin activity and if yes, what data model is suitable for it?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-create-a/m-p/259099#M1904</link>
      <description>&lt;P&gt;I meant _internal. You can search through this index &lt;/P&gt;

&lt;P&gt;index=_internal &lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2017 05:26:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-create-a/m-p/259099#M1904</guid>
      <dc:creator>hardikJsheth</dc:creator>
      <dc:date>2017-01-27T05:26:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Is it possible to create a correlation search on admin activity and if yes, what data model is suitable for it?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-create-a/m-p/259100#M1905</link>
      <description>&lt;P&gt;do i need admin access, to access this index.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2017 14:20:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-create-a/m-p/259100#M1905</guid>
      <dc:creator>Rocky31</dc:creator>
      <dc:date>2017-01-27T14:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Is it possible to create a correlation search on admin activity and if yes, what data model is suitable for it?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-create-a/m-p/259101#M1906</link>
      <description>&lt;P&gt;The _ indexes (_internal, _audit) are often not available to standard users...also they are not searched by default so try the index=_internal and see if anything appears, if not run a query to check what index access you have...&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:34:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-create-a/m-p/259101#M1906</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2020-09-29T12:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Is it possible to create a correlation search on admin activity and if yes, what data model is suitable for it?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-create-a/m-p/259102#M1907</link>
      <description>&lt;P&gt;index=_internal (action=&lt;EM&gt;edit&lt;/EM&gt;) user=admin&lt;BR /&gt;
| table _time,user,user_email,action,info&lt;/P&gt;

&lt;P&gt;this is the search string i using, i checked in the roles access, i don't have access for _internal.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:40:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-create-a/m-p/259102#M1907</guid>
      <dc:creator>Rocky31</dc:creator>
      <dc:date>2020-09-29T12:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Is it possible to create a correlation search on admin activity and if yes, what data model is suitable for it?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-create-a/m-p/259103#M1908</link>
      <description>&lt;P&gt;I use &lt;BR /&gt;
| eventcount summarize=f index=_* index=* | dedup index | table index&lt;/P&gt;

&lt;P&gt;FYI, but if you don't have _internal access you won't see the various sources you need...&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2017 00:38:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-create-a/m-p/259103#M1908</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2017-01-31T00:38:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Is it possible to create a correlation search on admin activity and if yes, what data model is suitable for it?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-create-a/m-p/259104#M1909</link>
      <description>&lt;P&gt;You may want to look at some of the audit dashboards in ES and consider using them as a starting point for the correlation search you want to write.  For example, the Search Audit dashboard has a panel that calculates run time, but it contains the search itself as well as the user and time.  Drilling into it you can see that is uses the macro search_activity and then works on that to format the output and calculate time.  You could potentially use that as a starting point and tweak to look at activity that a specific account name, like admin is doing.  Correlation searches do not need to use data models though it makes a lot of sense to in most cases when dealing with sensors and endpoints that can be heterogenous.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2017 00:23:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Is-it-possible-to-create-a/m-p/259104#M1909</guid>
      <dc:creator>jstoner_splunk</dc:creator>
      <dc:date>2017-02-02T00:23:04Z</dc:date>
    </item>
  </channel>
</rss>

