Hi, I am quite new with SPL searches and I need to urgently create the below searches, anyone can help?
- executable files download (.exe should be excluded due to the amount)
- big uploads made by users to external hosts
Assuming you have data available about the uploads and download made by users, both searches are possible. See the Splunk Security Essentials app (https://splunkbase.splunk.com/app/3435/) for examples.
Assuming you have data available about the uploads and download made by users, both searches are possible. See the Splunk Security Essentials app (https://splunkbase.splunk.com/app/3435/) for examples.