Alerting

Any common useful alerts for an environment with Windows and Redhat?

carefulrelish
New Member

Hi community,

I was wondering if there was a collection of useful alerts for an environment that has both Windows and Red Hat boxes such as errors and suspicious behavior. My team is looking at getting Splunk Enterprise Security in the future, but anything useful now for less advantage Splunk people would be great!

Thanks in advance!

0 Karma

muebel
SplunkTrust
SplunkTrust

Hi carefulrelish, check out the Common Information Model app (CIM) It makes use of data models to allow for a single searchable interface. This is part of the way that ES can use single correlation searches that search over disparate data sources. (windows and nix authentication events for instance)

Please let me know if this answers your question!

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...