<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk dashboard searching in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/splunk-dashboard-searching/m-p/290389#M39451</link>
    <description>&lt;P&gt;Not very familiar with FireEye logs but logs can be pretty straightforward at most times.  If source and destination IPs are visible in the logs, and you know what specific Malware attack to look up to then it's just a matter of identifying what time it occurred.&lt;/P&gt;

&lt;P&gt;And if the source is not available in the logs, you'll just have to index the logs that contain the source (most likely firewall and network logs) then try to correlate it with the logs that contain the Malware attack.&lt;/P&gt;

&lt;P&gt;Regarding the script that you're asking, you mean search query?&lt;/P&gt;</description>
    <pubDate>Tue, 16 May 2017 06:15:49 GMT</pubDate>
    <dc:creator>lloydknight</dc:creator>
    <dc:date>2017-05-16T06:15:49Z</dc:date>
    <item>
      <title>splunk dashboard searching</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/splunk-dashboard-searching/m-p/290383#M39445</link>
      <description>&lt;P&gt;on the splunk dashboard, is there a way to search for origin/source of a malware attack?&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 11:21:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/splunk-dashboard-searching/m-p/290383#M39445</guid>
      <dc:creator>sam3655</dc:creator>
      <dc:date>2017-05-12T11:21:12Z</dc:date>
    </item>
    <item>
      <title>Re: splunk dashboard searching</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/splunk-dashboard-searching/m-p/290384#M39446</link>
      <description>&lt;P&gt;your question is vague.&lt;/P&gt;

&lt;P&gt;Assuming you're indexing logs containing the Malware attack and given that you know what type of attacks were executed on a certain time, yes, you can search that malware attack.&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 11:36:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/splunk-dashboard-searching/m-p/290384#M39446</guid>
      <dc:creator>lloydknight</dc:creator>
      <dc:date>2017-05-12T11:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: splunk dashboard searching</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/splunk-dashboard-searching/m-p/290385#M39447</link>
      <description>&lt;P&gt;is there a script for the search?&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 12:35:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/splunk-dashboard-searching/m-p/290385#M39447</guid>
      <dc:creator>sam3655</dc:creator>
      <dc:date>2017-05-12T12:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: splunk dashboard searching</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/splunk-dashboard-searching/m-p/290386#M39448</link>
      <description>&lt;P&gt;are you looking at table or raw event data?&lt;BR /&gt;
Moreover, origin in the sense of ip look lookup? Can you share more about what do you see? &lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 13:10:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/splunk-dashboard-searching/m-p/290386#M39448</guid>
      <dc:creator>akocak</dc:creator>
      <dc:date>2017-05-12T13:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: splunk dashboard searching</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/splunk-dashboard-searching/m-p/290387#M39449</link>
      <description>&lt;P&gt;Yes.  NO.  Maybe. It depends.&lt;/P&gt;

&lt;P&gt;It depends on what you mean by "dashboard".  It depends on what &lt;STRONG&gt;kind&lt;/STRONG&gt; of attack.  It depends on what your organization actually puts in splunk. &lt;/P&gt;

&lt;P&gt;So, please update your question to be VERY specific.  &lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;We experienced an ABC attack, which&lt;BR /&gt;
had THIS effect on our&lt;BR /&gt;
organization/network/data. &lt;/P&gt;

&lt;P&gt;What log data would we need to have&lt;BR /&gt;
captured in order to determine the&lt;BR /&gt;
source of the attack?  What resources&lt;BR /&gt;
are available in the splunk platform&lt;BR /&gt;
to help us track that down?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Fri, 12 May 2017 13:45:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/splunk-dashboard-searching/m-p/290387#M39449</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-05-12T13:45:56Z</dc:date>
    </item>
    <item>
      <title>Re: splunk dashboard searching</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/splunk-dashboard-searching/m-p/290388#M39450</link>
      <description>&lt;P&gt;FireEye monitors our network and catches Malware Callbacks, I'm looking for a script tell me who sent the Malware?&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 14:14:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/splunk-dashboard-searching/m-p/290388#M39450</guid>
      <dc:creator>sam3655</dc:creator>
      <dc:date>2017-05-12T14:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: splunk dashboard searching</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/splunk-dashboard-searching/m-p/290389#M39451</link>
      <description>&lt;P&gt;Not very familiar with FireEye logs but logs can be pretty straightforward at most times.  If source and destination IPs are visible in the logs, and you know what specific Malware attack to look up to then it's just a matter of identifying what time it occurred.&lt;/P&gt;

&lt;P&gt;And if the source is not available in the logs, you'll just have to index the logs that contain the source (most likely firewall and network logs) then try to correlate it with the logs that contain the Malware attack.&lt;/P&gt;

&lt;P&gt;Regarding the script that you're asking, you mean search query?&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2017 06:15:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/splunk-dashboard-searching/m-p/290389#M39451</guid>
      <dc:creator>lloydknight</dc:creator>
      <dc:date>2017-05-16T06:15:49Z</dc:date>
    </item>
  </channel>
</rss>

