All Apps and Add-ons

Infosec App for Splunk Dashboard- Malware Dashboard

crizelle
Explorer

Hi,

Will the result on the Malware dashboard also change when we already clean the detected malware?

Thanks!

0 Karma
1 Solution

igifrin_splunk
Splunk Employee
Splunk Employee

Hi @crizelle, the logic here is not specific to the InfoSec app but applies to many other dashboards you see in Splunk:

  • Malware events come into Splunk with time stamps
  • When you look at the Malware dashboard, it displays events in the past 24 hours by default but you can select a different time window (see screenshot below)
  • If your anti-malware tool does not keep reporting on old malware events, the events will not show in the new time window

InfoSec app: Malware dashboard

View solution in original post

igifrin_splunk
Splunk Employee
Splunk Employee

Hi @crizelle, the logic here is not specific to the InfoSec app but applies to many other dashboards you see in Splunk:

  • Malware events come into Splunk with time stamps
  • When you look at the Malware dashboard, it displays events in the past 24 hours by default but you can select a different time window (see screenshot below)
  • If your anti-malware tool does not keep reporting on old malware events, the events will not show in the new time window

InfoSec app: Malware dashboard

Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...