<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk hash search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-hash-search/m-p/549543#M155934</link>
    <description>&lt;P&gt;We have a list of hash values for a possible ransomeware attack and need to see if those hashes were ever in our environment.&lt;/P&gt;</description>
    <pubDate>Tue, 27 Apr 2021 23:15:47 GMT</pubDate>
    <dc:creator>drdreday</dc:creator>
    <dc:date>2021-04-27T23:15:47Z</dc:date>
    <item>
      <title>Splunk hash search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-hash-search/m-p/549531#M155926</link>
      <description>&lt;P&gt;how do you search for hash value in splunk? Do we need to use a specific index?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2021 21:11:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-hash-search/m-p/549531#M155926</guid>
      <dc:creator>drdreday</dc:creator>
      <dc:date>2021-04-27T21:11:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk hash search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-hash-search/m-p/549540#M155931</link>
      <description>&lt;P&gt;More words are needed to understand your use case.&amp;nbsp; Hash value of what?&amp;nbsp; What problem are you trying to solve?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2021 22:54:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-hash-search/m-p/549540#M155931</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-04-27T22:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk hash search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-hash-search/m-p/549543#M155934</link>
      <description>&lt;P&gt;We have a list of hash values for a possible ransomeware attack and need to see if those hashes were ever in our environment.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2021 23:15:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-hash-search/m-p/549543#M155934</guid>
      <dc:creator>drdreday</dc:creator>
      <dc:date>2021-04-27T23:15:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk hash search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-hash-search/m-p/549545#M155936</link>
      <description>&lt;P&gt;If you have the hashes in Splunk - perhaps reported by a firewall or email server - then, yes, you can search for them.&amp;nbsp; They will be in the index in which they were saved.&lt;/P&gt;&lt;P&gt;If the hashes are not indexed in Splunk then you'll have a hard time searching for them.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2021 23:42:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-hash-search/m-p/549545#M155936</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-04-27T23:42:36Z</dc:date>
    </item>
  </channel>
</rss>

