<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Azure defender advanced hunting to Splunk SPL in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Azure-defender-advanced-hunting-to-Splunk-SPL/m-p/689982#M235056</link>
    <description>&lt;P&gt;So basically I'd like to do concatenation between DeviceProcess and DeviceRegistry events in advanced hunting query | advhunt&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jun 2024 13:15:05 GMT</pubDate>
    <dc:creator>heskez</dc:creator>
    <dc:date>2024-06-07T13:15:05Z</dc:date>
    <item>
      <title>Azure defender advanced hunting to Splunk SPL</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Azure-defender-advanced-hunting-to-Splunk-SPL/m-p/689839#M235022</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;I am having an issue in Advanced hunting for Defender app in Splunk&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="https://splunkbase.splunk.com/app/5518" target="_blank" rel="noopener noreferrer"&gt;https://splunkbase.splunk.com/app/5518&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;My original KQL query in azure contains | JOIN KIND INNER. Is such syntax also possible in SPL?&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 06 Jun 2024 12:57:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Azure-defender-advanced-hunting-to-Splunk-SPL/m-p/689839#M235022</guid>
      <dc:creator>heskez</dc:creator>
      <dc:date>2024-06-06T12:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: Azure defender advanced hunting to Splunk SPL</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Azure-defender-advanced-hunting-to-Splunk-SPL/m-p/689844#M235023</link>
      <description>&lt;P&gt;Yes, SPL has a join command, but it should be avoided because it doesn't perform well.&amp;nbsp; See &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/SearchReference/Join" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.2.1/SearchReference/Join&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2024 14:37:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Azure-defender-advanced-hunting-to-Splunk-SPL/m-p/689844#M235023</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-06-06T14:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: Azure defender advanced hunting to Splunk SPL</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Azure-defender-advanced-hunting-to-Splunk-SPL/m-p/689977#M235055</link>
      <description>&lt;P&gt;Thanks for your answer. I'm not sure if this is what I want. Because the advanced hunting app requires an API call with a limit of calls, I start doing a call on DeviceProcessEvents. Then I'm not sure if I need to do another API call on DeviceRegistryEvents, since I'd like to joint these two instances.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 12:56:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Azure-defender-advanced-hunting-to-Splunk-SPL/m-p/689977#M235055</guid>
      <dc:creator>heskez</dc:creator>
      <dc:date>2024-06-07T12:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: Azure defender advanced hunting to Splunk SPL</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Azure-defender-advanced-hunting-to-Splunk-SPL/m-p/689982#M235056</link>
      <description>&lt;P&gt;So basically I'd like to do concatenation between DeviceProcess and DeviceRegistry events in advanced hunting query | advhunt&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 13:15:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Azure-defender-advanced-hunting-to-Splunk-SPL/m-p/689982#M235056</guid>
      <dc:creator>heskez</dc:creator>
      <dc:date>2024-06-07T13:15:05Z</dc:date>
    </item>
  </channel>
</rss>

