<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Any common useful alerts for an environment with Windows and Redhat? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Any-common-useful-alerts-for-an-environment-with-Windows-and/m-p/273345#M5015</link>
    <description>&lt;P&gt;Hi community,&lt;/P&gt;

&lt;P&gt;I was wondering if there was a collection of useful alerts for an environment that has both Windows and Red Hat boxes such as errors and suspicious behavior. My team is looking at getting Splunk Enterprise Security in the future, but anything useful now for less advantage Splunk people would be great!&lt;/P&gt;

&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Mon, 18 Jul 2016 23:48:19 GMT</pubDate>
    <dc:creator>carefulrelish</dc:creator>
    <dc:date>2016-07-18T23:48:19Z</dc:date>
    <item>
      <title>Any common useful alerts for an environment with Windows and Redhat?</title>
      <link>https://community.splunk.com/t5/Alerting/Any-common-useful-alerts-for-an-environment-with-Windows-and/m-p/273345#M5015</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;

&lt;P&gt;I was wondering if there was a collection of useful alerts for an environment that has both Windows and Red Hat boxes such as errors and suspicious behavior. My team is looking at getting Splunk Enterprise Security in the future, but anything useful now for less advantage Splunk people would be great!&lt;/P&gt;

&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2016 23:48:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Any-common-useful-alerts-for-an-environment-with-Windows-and/m-p/273345#M5015</guid>
      <dc:creator>carefulrelish</dc:creator>
      <dc:date>2016-07-18T23:48:19Z</dc:date>
    </item>
    <item>
      <title>Re: Any common useful alerts for an environment with Windows and Redhat?</title>
      <link>https://community.splunk.com/t5/Alerting/Any-common-useful-alerts-for-an-environment-with-Windows-and/m-p/273346#M5016</link>
      <description>&lt;P&gt;Hi carefulrelish, check out the &lt;A href="https://splunkbase.splunk.com/app/1621/"&gt;Common Information Model&lt;/A&gt; app (CIM) It makes use of data models to allow for a single searchable interface. This is part of the way that ES can use single correlation searches that search over disparate data sources. (windows and nix authentication events for instance)&lt;/P&gt;

&lt;P&gt;Please let me know if this answers your question!&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2016 14:53:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Any-common-useful-alerts-for-an-environment-with-Windows-and/m-p/273346#M5016</guid>
      <dc:creator>muebel</dc:creator>
      <dc:date>2016-07-19T14:53:48Z</dc:date>
    </item>
  </channel>
</rss>

