Alerting

List of common related security alerts

mcoleman2
Explorer

Is there a list of common security related alerts somewhere? Like a cheat sheet of security alerts on various types of servers. I know there's the Enterprise Security app, but it's too expensive for us.

Alerts like: multiple failed login attempts in a short period of time, an abnormal spike in traffic on a webserver, registry changes in windows machines, etc

Tags (1)
0 Karma

AndySplunks
Communicator

There isn't a specific list I've seen anywhere. I've found the generic alerts in Enterprise Security to be mostly useless. Your IDS / IPS or the native systems should be handling a fair majority of those use cases.

What sorts of systems are you sending to Splunk?

Example Use Cases For Windows:
- Who can modify user accounts? Alert if anyone else does it.
- Are there any accounts being used that don't match your naming standards?
- Are there any accounts of a specific standard behaving differently? For example, is a server account logging in to an endpoint?
- List item

0 Karma

mcoleman2
Explorer

I'm sending Windows and Linux logs to Splunk.

0 Karma

AndySplunks
Communicator

Linux is a little tougher. I've yet to find too many good alerts.

This site, Malware Archaeology, has amazing resources for monitoring Windows systems via Splunk. I've implemented a fair number of their use cases.

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...