All Apps and Add-ons

Database Intrusion Detection

praveentandra
New Member

Does Splunk have any modules to detect database intrusion i.e. indicate anomalies in access patterns? Or any functionality to process database logs.

Tags (2)
0 Karma

DalJeanis
Legend

The underlying issue with the question is that anomalies are relative to something... your particular users, your particular data, your particular applications, your particular seasonality, and so on.

In some companies, accessing a production database on a night or a weekend would be an anomaly. Others, FAILURE to access the database would be an anomaly.

Splunk has lots of features for detecting and analyzing unusual or interesting events.

The first step is to get the logs into splunk. Then, ask a question about access patterns, pull the relevant data, and get yourself a simple answer. Repeat, repeat, repeat.

Whenever you find the answer is not simple, or the data is not understandable, then post some non-confidential details about the issue in a new question and we will help you figure out how to think about the data you have, or how to reorganize it to make sense.

But the first step is acquiring a feed from the audit logs themselves, and getting them into splunk (or any other awesome tool) so that they can be examined.

0 Karma

lguinn2
Legend

Splunk does not have "modules" - instead there are "apps." Most apps are free, and you can find them at http://splunkbase.splunk.com

There are several free apps that help you ingest and analyze database logs.
There is also the Splunk App for Enterprise Security, which does a whole lot more than that, but is not free. Here is a fact sheet for the Splunk App for Enterprise Security.

0 Karma

praveentandra
New Member

Could you point me to more detailed documentation? I am looking for i) auditing access to sensitive data ii) anomaly in access patterns; specifically for SQL Server database.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...