All Apps and Add-ons

Help creating two CWS searches

dzejsonborn
New Member

Hi, I am quite new with SPL searches and I need to urgently create the below searches, anyone can help?

- executable files download (.exe should be excluded due to the amount)

- big uploads made by users to external hosts

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Assuming you have data available about the uploads and download made by users, both searches are possible. See the Splunk Security Essentials app (https://splunkbase.splunk.com/app/3435/) for examples.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Assuming you have data available about the uploads and download made by users, both searches are possible. See the Splunk Security Essentials app (https://splunkbase.splunk.com/app/3435/) for examples.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...