<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Wildcard for domain search in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Wildcard-for-domain-search/m-p/452521#M6312</link>
    <description>&lt;P&gt;I am trying to find the domain that came in the logs but were faked to look similar for our domain.&lt;BR /&gt;
So if my domain is abc.co I would like to list all entries that came for abc.co.xyz.com, abc.co.aaa.com, etc.&lt;BR /&gt;
Thanks!&lt;/P&gt;</description>
    <pubDate>Fri, 10 May 2019 10:29:10 GMT</pubDate>
    <dc:creator>johnde</dc:creator>
    <dc:date>2019-05-10T10:29:10Z</dc:date>
    <item>
      <title>Wildcard for domain search</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Wildcard-for-domain-search/m-p/452521#M6312</link>
      <description>&lt;P&gt;I am trying to find the domain that came in the logs but were faked to look similar for our domain.&lt;BR /&gt;
So if my domain is abc.co I would like to list all entries that came for abc.co.xyz.com, abc.co.aaa.com, etc.&lt;BR /&gt;
Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 10:29:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Wildcard-for-domain-search/m-p/452521#M6312</guid>
      <dc:creator>johnde</dc:creator>
      <dc:date>2019-05-10T10:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: Wildcard for domain search</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Wildcard-for-domain-search/m-p/452522#M6313</link>
      <description>&lt;P&gt;Please provide sample data for this. You can write the SPL in 1000's of ways if you don't provide sample data&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 14:20:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Wildcard-for-domain-search/m-p/452522#M6313</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2019-05-10T14:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: Wildcard for domain search</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Wildcard-for-domain-search/m-p/452523#M6314</link>
      <description>&lt;P&gt;Thanks for the reply @koshyk .&lt;BR /&gt;
I am new to SPL and still trying to figure out the right approach, what I am trying to find out is if someone faked our login page and redirected a user when they login with their credentials to our page.&lt;BR /&gt;
Let's say our login page is is login.mydomain.co and someone created a sub-domain with our login page name, login.mydomain.co.fakedomain.com and this looks similar to our login page. Once a user enters the username password they are redirected to mydomain.co. I wanted to see if any of our users clicked on that link and entered the credentials based on the redirect.&lt;BR /&gt;
fakedomain.com is not constant and it can be any value.&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 14:48:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Wildcard-for-domain-search/m-p/452523#M6314</guid>
      <dc:creator>johnde</dc:creator>
      <dc:date>2019-05-10T14:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: Wildcard for domain search</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Wildcard-for-domain-search/m-p/452524#M6315</link>
      <description>&lt;P&gt;Can't you just do &lt;CODE&gt;myfield=abc.co*&lt;/CODE&gt;?  Also, check out this app:&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/3376/"&gt;https://splunkbase.splunk.com/app/3376/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 18:09:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Wildcard-for-domain-search/m-p/452524#M6315</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-05-10T18:09:07Z</dc:date>
    </item>
  </channel>
</rss>

