<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk search to find out CVE-2021-44228(Apache Log4j Remote Code Execution） in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-to-find-out-CVE-2021-44228-Apache-Log4j-Remote/m-p/578142#M201486</link>
    <description>&lt;P&gt;Hi Team&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to find out recent&amp;nbsp;CVE-2021-44228( log4j)&lt;/P&gt;&lt;P&gt;I tried "&amp;nbsp;index=aws *log4j*", nut not sure how to find out and create an alert based on this Vulnerability.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone help me with the correct search and explain how to create an alert based on this vulnerability&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Dec 2021 00:58:49 GMT</pubDate>
    <dc:creator>jaibalaraman</dc:creator>
    <dc:date>2021-12-13T00:58:49Z</dc:date>
    <item>
      <title>Splunk search to find out CVE-2021-44228(Apache Log4j Remote Code Execution）</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-to-find-out-CVE-2021-44228-Apache-Log4j-Remote/m-p/578142#M201486</link>
      <description>&lt;P&gt;Hi Team&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to find out recent&amp;nbsp;CVE-2021-44228( log4j)&lt;/P&gt;&lt;P&gt;I tried "&amp;nbsp;index=aws *log4j*", nut not sure how to find out and create an alert based on this Vulnerability.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone help me with the correct search and explain how to create an alert based on this vulnerability&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 00:58:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-to-find-out-CVE-2021-44228-Apache-Log4j-Remote/m-p/578142#M201486</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2021-12-13T00:58:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search to find out CVE-2021-44228(Apache Log4j Remote Code Execution）</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-to-find-out-CVE-2021-44228-Apache-Log4j-Remote/m-p/578143#M201487</link>
      <description>&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/blog/security/log-jammin-log4j-2-rce.html" target="_blank"&gt;https://www.splunk.com/en_us/blog/security/log-jammin-log4j-2-rce.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 02:52:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-to-find-out-CVE-2021-44228-Apache-Log4j-Remote/m-p/578143#M201487</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2021-12-13T02:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search to find out CVE-2021-44228(Apache Log4j Remote Code Execution）</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-to-find-out-CVE-2021-44228-Apache-Log4j-Remote/m-p/578153#M201489</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, i tried the page, but the search is not working for me&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaibalaraman_0-1639375938969.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17206i1524D6068A5B35CA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaibalaraman_0-1639375938969.png" alt="jaibalaraman_0-1639375938969.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Could you please me to understand why its not working&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 06:12:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-to-find-out-CVE-2021-44228-Apache-Log4j-Remote/m-p/578153#M201489</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2021-12-13T06:12:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search to find out CVE-2021-44228(Apache Log4j Remote Code Execution）</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-to-find-out-CVE-2021-44228-Apache-Log4j-Remote/m-p/578163#M201491</link>
      <description>&lt;P&gt;What are you trying to do?&lt;/P&gt;&lt;P&gt;Are you trying to locate the vulnerability within your infrastructure? You can't do that with splunk alone.&lt;/P&gt;&lt;P&gt;Or are you trying to see if someone already attempted to exploit it? In this case you simply might not have recorded any exploitation attempts.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 07:28:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-to-find-out-CVE-2021-44228-Apache-Log4j-Remote/m-p/578163#M201491</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-12-13T07:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search to find out CVE-2021-44228(Apache Log4j Remote Code Execution）</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-to-find-out-CVE-2021-44228-Apache-Log4j-Remote/m-p/578229#M201510</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes i am trying to find out list out servers affected with this vulnerability and what to find out is there any new attempt was initiated with the user agent.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 18:06:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-to-find-out-CVE-2021-44228-Apache-Log4j-Remote/m-p/578229#M201510</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2021-12-13T18:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk search to find out CVE-2021-44228(Apache Log4j Remote Code Execution）</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-search-to-find-out-CVE-2021-44228-Apache-Log4j-Remote/m-p/578353#M201556</link>
      <description>&lt;P&gt;OK. To find which of your servers are vulnerable (use the vulnerable library) you need a completely different tool - some form of software inventory solution and/or vulnerability scanner/manager.&lt;/P&gt;&lt;P&gt;To find out whether someone already tried to exploit this CVE, you have a nice splunk blog post &lt;A href="https://www.splunk.com/en_us/blog/security/log4shell-detecting-log4j-vulnerability-cve-2021-44228-continued.html" target="_blank"&gt;https://www.splunk.com/en_us/blog/security/log4shell-detecting-log4j-vulnerability-cve-2021-44228-continued.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 17:22:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-search-to-find-out-CVE-2021-44228-Apache-Log4j-Remote/m-p/578353#M201556</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-12-14T17:22:25Z</dc:date>
    </item>
  </channel>
</rss>

