<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: integrate splunk enterprise security with  Active Directory 、Linux system log  etc. to detect security events  best practices in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/integrate-splunk-enterprise-security-with-Active-Directory-Linux/m-p/423494#M5322</link>
    <description>&lt;P&gt;The above link takes you to windows infra app, which is an app that uses the data for dashboard monitoring and still needs other add-ons [ like the one i have mentioned earlier]. Pls see the documentation &lt;A href="https://docs.splunk.com/Documentation/MSApp/latest/MSInfra/AbouttheSplunkAppforMSInfrastructure"&gt;https://docs.splunk.com/Documentation/MSApp/latest/MSInfra/AbouttheSplunkAppforMSInfrastructure&lt;/A&gt;  (esp, the how does it work and get windows data and active data inputs sections)&lt;/P&gt;

&lt;P&gt;Use &lt;A href="https://splunkbase.splunk.com/app/2968/"&gt;https://splunkbase.splunk.com/app/2968/&lt;/A&gt; and associated docs for analysing and validating the data.&lt;/P&gt;

&lt;P&gt;Oracle - it depends on what you need.&lt;/P&gt;</description>
    <pubDate>Wed, 06 Mar 2019 14:32:20 GMT</pubDate>
    <dc:creator>lakshman239</dc:creator>
    <dc:date>2019-03-06T14:32:20Z</dc:date>
    <item>
      <title>integrate splunk enterprise security with  Active Directory 、Linux system log  etc. to detect security events  best practices</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/integrate-splunk-enterprise-security-with-Active-Directory-Linux/m-p/423491#M5319</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;

&lt;P&gt;I'm a splunk es novice.  I would like to ask about best practices for ingesting  data into ES .&lt;/P&gt;

&lt;P&gt;for example:&lt;/P&gt;

&lt;P&gt;1、 I want to intergrate  Active Directory to ES to  trigger something worth noting in Enterprise Security. I Know I need an  Add-on,  but there are a lot of add-on for  Active Directory on the splunk base. So what is the add-on that splunk officially recommends?  Currently I want to integrate splunk es with Active Directory, Linux system logs (secure, message, audit.log), network traffic, oracle database, etc.&lt;/P&gt;

&lt;P&gt;2、By default, splunk enterprise allows users to integrate which logs so that it can directly trigger interesting security events in the ES(means I don't need to do too much configuration).&lt;/P&gt;

&lt;P&gt;3、for example,splunk  Enterprise Security built-in ORACLE data model and TA  , the official documentation does not seem to tell me,  which log file of ORACLE  can I  intergrate   to splunk ES?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2019 11:34:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/integrate-splunk-enterprise-security-with-Active-Directory-Linux/m-p/423491#M5319</guid>
      <dc:creator>bestSplunker</dc:creator>
      <dc:date>2019-03-06T11:34:35Z</dc:date>
    </item>
    <item>
      <title>Re: integrate splunk enterprise security with  Active Directory 、Linux system log  etc. to detect security events  best practices</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/integrate-splunk-enterprise-security-with-Active-Directory-Linux/m-p/423492#M5320</link>
      <description>&lt;OL&gt;
&lt;LI&gt;You can use &lt;A href="https://splunkbase.splunk.com/app/3207/"&gt;https://splunkbase.splunk.com/app/3207/&lt;/A&gt;  to get all events from Active Directory  [ This can also be configured to send windows event logs - security/application/system if you are not using Splunk Add on for windows - &lt;A href="https://splunkbase.splunk.com/app/742/"&gt;https://splunkbase.splunk.com/app/742/&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Not fully true. If you have your data sources analysed and made them CIM compliance - &lt;A href="https://splunkbase.splunk.com/app/1621/"&gt;https://splunkbase.splunk.com/app/1621/&lt;/A&gt; (comes with ES) and have enabled some or your required correlations searches [ comes out of box], yes then it can create notables.&lt;/LI&gt;
&lt;LI&gt;Are you talking about &lt;A href="https://splunkbase.splunk.com/app/1910/#/details"&gt;https://splunkbase.splunk.com/app/1910/#/details&lt;/A&gt;?  There is no need to use supplied TA (the ones that come with ES, unless you have a strong reason). You can download and install the TA's which you need. &lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 06 Mar 2019 13:29:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/integrate-splunk-enterprise-security-with-Active-Directory-Linux/m-p/423492#M5320</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-03-06T13:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: integrate splunk enterprise security with  Active Directory 、Linux system log  etc. to detect security events  best practices</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/integrate-splunk-enterprise-security-with-Active-Directory-Linux/m-p/423493#M5321</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/177803"&gt;@lakshman239&lt;/a&gt; &lt;BR /&gt;
about  the first question, &lt;A href="https://answers.splunk.com/answers/230222/how-to-integrate-splunk-for-enterprise-security-wi.html" target="_blank"&gt;https://answers.splunk.com/answers/230222/how-to-integrate-splunk-for-enterprise-security-wi.html&lt;/A&gt; ,This post has an accepted answer "Splunk App for Windows Infrastructure". Since each person's recommended add-ons are different, which add-on component is splunk's official recommendation preferred that In order to be more suitable for ES&lt;/P&gt;

&lt;P&gt;about the sencond question, Is there a tutorial that tells me how to analyze the data step by step to make a CIM-compliant case?&lt;/P&gt;

&lt;P&gt;about the third question, Which oracle log file do I need to monitor? I checked configuration files of Splunk_TA_Oracle , I didn't find the built-in inputs.conf,&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:30:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/integrate-splunk-enterprise-security-with-Active-Directory-Linux/m-p/423493#M5321</guid>
      <dc:creator>bestSplunker</dc:creator>
      <dc:date>2020-09-29T23:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: integrate splunk enterprise security with  Active Directory 、Linux system log  etc. to detect security events  best practices</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/integrate-splunk-enterprise-security-with-Active-Directory-Linux/m-p/423494#M5322</link>
      <description>&lt;P&gt;The above link takes you to windows infra app, which is an app that uses the data for dashboard monitoring and still needs other add-ons [ like the one i have mentioned earlier]. Pls see the documentation &lt;A href="https://docs.splunk.com/Documentation/MSApp/latest/MSInfra/AbouttheSplunkAppforMSInfrastructure"&gt;https://docs.splunk.com/Documentation/MSApp/latest/MSInfra/AbouttheSplunkAppforMSInfrastructure&lt;/A&gt;  (esp, the how does it work and get windows data and active data inputs sections)&lt;/P&gt;

&lt;P&gt;Use &lt;A href="https://splunkbase.splunk.com/app/2968/"&gt;https://splunkbase.splunk.com/app/2968/&lt;/A&gt; and associated docs for analysing and validating the data.&lt;/P&gt;

&lt;P&gt;Oracle - it depends on what you need.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2019 14:32:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/integrate-splunk-enterprise-security-with-Active-Directory-Linux/m-p/423494#M5322</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-03-06T14:32:20Z</dc:date>
    </item>
  </channel>
</rss>

