<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: searching in splunk indexes in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/searching-in-splunk-indexes/m-p/697687#M236982</link>
    <description>&lt;P&gt;HI,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I need to find secrets (passwords, api-tokens, etc.) in all data (events) in all indexes that are in splunk, the question is in the approach: how to do this so as not to overload splunk.&lt;/P&gt;</description>
    <pubDate>Thu, 29 Aug 2024 09:40:07 GMT</pubDate>
    <dc:creator>user487596</dc:creator>
    <dc:date>2024-08-29T09:40:07Z</dc:date>
    <item>
      <title>searching in splunk indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/searching-in-splunk-indexes/m-p/697680#M236980</link>
      <description>&lt;P&gt;Hello everyone! How can we solve the problem of searching for secrets in all or some splunk indexes so that splunk is not heavily loaded: how can this be implemented? (approach).&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is obvious that the list of indexes needs to be limited. What else?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 08:38:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/searching-in-splunk-indexes/m-p/697680#M236980</guid>
      <dc:creator>user487596</dc:creator>
      <dc:date>2024-08-29T08:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: searching in splunk indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/searching-in-splunk-indexes/m-p/697686#M236981</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/268899"&gt;@user487596&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;could you better describe your requisite?&lt;/P&gt;&lt;P&gt;In Splunk access to data is managed at index level, in other words, you can define for each role, which are the indexes that the users with that role can access.&lt;/P&gt;&lt;P&gt;In addition, it's also possible to add some additional restrictions, but always at Role level, not user level.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 09:34:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/searching-in-splunk-indexes/m-p/697686#M236981</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-08-29T09:34:51Z</dc:date>
    </item>
    <item>
      <title>Re: searching in splunk indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/searching-in-splunk-indexes/m-p/697687#M236982</link>
      <description>&lt;P&gt;HI,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I need to find secrets (passwords, api-tokens, etc.) in all data (events) in all indexes that are in splunk, the question is in the approach: how to do this so as not to overload splunk.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 09:40:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/searching-in-splunk-indexes/m-p/697687#M236982</guid>
      <dc:creator>user487596</dc:creator>
      <dc:date>2024-08-29T09:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: searching in splunk indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/searching-in-splunk-indexes/m-p/697688#M236983</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/268899"&gt;@user487596&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Splunk is a search engine, so you can use it for this:&lt;/P&gt;&lt;P&gt;you must know the rules (e.g. searching for the password word) and then apply to the indexes.&lt;/P&gt;&lt;P&gt;At first I'd start identifying the login and create user actions for each environment in your infrastructure (e.g. in windows these action are identifed with EventCode = 4624 and 4720), then you can run searches with those specific filters to see if there are clear text passwords.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 09:46:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/searching-in-splunk-indexes/m-p/697688#M236983</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-08-29T09:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: searching in splunk indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/searching-in-splunk-indexes/m-p/697982#M237077</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&amp;nbsp;It's pretty clear what to look for, the question is how to do it in all indexes without loading splunk&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 12:54:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/searching-in-splunk-indexes/m-p/697982#M237077</guid>
      <dc:creator>user487596</dc:creator>
      <dc:date>2024-09-02T12:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: searching in splunk indexes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/searching-in-splunk-indexes/m-p/697984#M237079</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/268899"&gt;@user487596&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;sorry but I don't understand: what do you mean with "&lt;SPAN&gt;in all indexes without loading splunk"?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You could use APIs to access Splunk from your application without using the Splunk GUI.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 13:06:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/searching-in-splunk-indexes/m-p/697984#M237079</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-09-02T13:06:27Z</dc:date>
    </item>
  </channel>
</rss>

