Alerting

Automating queries based on FireEye "malware-object detected"

Thuan
Explorer

We currently have fireeye allerts coming in as log events that will be indexed. Some that are labeled as "malware-object detected" are currently manually processed by our analysts. They collect various fields (source/destnation IPs, time stamp, etc.), and build a query based on other logs (proxy, dns, exchange, etc.) as a way to build a "context" of the possible infection.
The idea is to automate this query search process every time a "malware-obeject detected" log is received and indexed.
May I get some pointers from you on how to proceed in terms of techniques and documentation?
Thank you.

Tags (2)
0 Karma

satishsdange
Builder

There is a cool app for FireEye devices https://splunkbase.splunk.com/app/1845/. This might address your problem.

0 Karma
Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability As businesses scale ...