Alerting

Automating queries based on FireEye "malware-object detected"

Thuan
Explorer

We currently have fireeye allerts coming in as log events that will be indexed. Some that are labeled as "malware-object detected" are currently manually processed by our analysts. They collect various fields (source/destnation IPs, time stamp, etc.), and build a query based on other logs (proxy, dns, exchange, etc.) as a way to build a "context" of the possible infection.
The idea is to automate this query search process every time a "malware-obeject detected" log is received and indexed.
May I get some pointers from you on how to proceed in terms of techniques and documentation?
Thank you.

Tags (2)
0 Karma

satishsdange
Builder

There is a cool app for FireEye devices https://splunkbase.splunk.com/app/1845/. This might address your problem.

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...