<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Enterprise security: What is tag=ids for cim_Intrusion_Detection_indexes? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-security-What-is-tag-ids-for-cim-Intrusion/m-p/418166#M5094</link>
    <description>&lt;P&gt;That really depends on the TA. For proper tagging and event typing, you need the data normalised.&lt;/P&gt;

&lt;P&gt;This means, in the first step, that all information from the events is extracted as required by a certain data model. Tags get applied after the field extractions. These are kind of the categorisation you were talking about.&lt;/P&gt;

&lt;P&gt;For further info, look at the &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.1/Knowledge/Searchtimeoperationssequence"&gt;order of search time operations&lt;/A&gt; in the docs. &lt;/P&gt;

&lt;P&gt;Skalli&lt;/P&gt;</description>
    <pubDate>Thu, 08 Aug 2019 10:20:01 GMT</pubDate>
    <dc:creator>skalliger</dc:creator>
    <dc:date>2019-08-08T10:20:01Z</dc:date>
    <item>
      <title>Splunk Enterprise security: What is tag=ids for cim_Intrusion_Detection_indexes?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-security-What-is-tag-ids-for-cim-Intrusion/m-p/418162#M5090</link>
      <description>&lt;P&gt;In ES, the constraint for Intrusion Detection is &lt;STRONG&gt;(&lt;CODE&gt;cim_Intrusion_Detection_indexes&lt;/CODE&gt;) tag=ids tag=attack&lt;/STRONG&gt;. &lt;/P&gt;

&lt;P&gt;What is the &lt;CODE&gt;tag=ids&lt;/CODE&gt; part?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2019 19:24:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-security-What-is-tag-ids-for-cim-Intrusion/m-p/418162#M5090</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2019-07-30T19:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise security: What is tag=ids for cim_Intrusion_Detection_indexes?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-security-What-is-tag-ids-for-cim-Intrusion/m-p/418163#M5091</link>
      <description>&lt;P&gt;Just found out that the following speaks about it - &lt;A href="https://docs.splunk.com/Documentation/PCI/3.8.0/Install/IDSIPSAlertActivity"&gt;IDS/IPS Alert Activity&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I - Intrusion, D - detection. Not sure about the S...&lt;/P&gt;

&lt;P&gt;It says to use - &lt;CODE&gt;tag=ids tag=attack&lt;/CODE&gt; or &lt;CODE&gt;ids_attack&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 14:03:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-security-What-is-tag-ids-for-cim-Intrusion/m-p/418163#M5091</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2019-07-31T14:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise security: What is tag=ids for cim_Intrusion_Detection_indexes?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-security-What-is-tag-ids-for-cim-Intrusion/m-p/418164#M5092</link>
      <description>&lt;P&gt;What's your problem? Do you just want to understand what the tag ids is there for? IDS usually stands for Intrusion Detection System (which may also be an IPS - intrusion prevention system). This tag gets applied by a TA which has normalized the data.&lt;/P&gt;

&lt;P&gt;Skalli&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 15:09:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-security-What-is-tag-ids-for-cim-Intrusion/m-p/418164#M5092</guid>
      <dc:creator>skalliger</dc:creator>
      <dc:date>2019-07-31T15:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise security: What is tag=ids for cim_Intrusion_Detection_indexes?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-security-What-is-tag-ids-for-cim-Intrusion/m-p/418165#M5093</link>
      <description>&lt;P&gt;"Just" trying to understand ES...&lt;/P&gt;

&lt;P&gt;You are saying -&lt;BR /&gt;
-- This tag gets applied by a TA which has normalized the data.&lt;/P&gt;

&lt;P&gt;Does the TA normalize the data or &lt;EM&gt;only&lt;/EM&gt; categorize it by applying the proper tags? &lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 17:12:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-security-What-is-tag-ids-for-cim-Intrusion/m-p/418165#M5093</guid>
      <dc:creator>danielbb</dc:creator>
      <dc:date>2019-08-07T17:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise security: What is tag=ids for cim_Intrusion_Detection_indexes?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-security-What-is-tag-ids-for-cim-Intrusion/m-p/418166#M5094</link>
      <description>&lt;P&gt;That really depends on the TA. For proper tagging and event typing, you need the data normalised.&lt;/P&gt;

&lt;P&gt;This means, in the first step, that all information from the events is extracted as required by a certain data model. Tags get applied after the field extractions. These are kind of the categorisation you were talking about.&lt;/P&gt;

&lt;P&gt;For further info, look at the &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.1/Knowledge/Searchtimeoperationssequence"&gt;order of search time operations&lt;/A&gt; in the docs. &lt;/P&gt;

&lt;P&gt;Skalli&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2019 10:20:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-security-What-is-tag-ids-for-cim-Intrusion/m-p/418166#M5094</guid>
      <dc:creator>skalliger</dc:creator>
      <dc:date>2019-08-08T10:20:01Z</dc:date>
    </item>
  </channel>
</rss>

