All Apps and Add-ons

Infosec App for Splunk Dashboard- Malware Dashboard

crizelle
Explorer

Hi,

Will the result on the Malware dashboard also change when we already clean the detected malware?

Thanks!

0 Karma
1 Solution

igifrin_splunk
Splunk Employee
Splunk Employee

Hi @crizelle, the logic here is not specific to the InfoSec app but applies to many other dashboards you see in Splunk:

  • Malware events come into Splunk with time stamps
  • When you look at the Malware dashboard, it displays events in the past 24 hours by default but you can select a different time window (see screenshot below)
  • If your anti-malware tool does not keep reporting on old malware events, the events will not show in the new time window

InfoSec app: Malware dashboard

View solution in original post

igifrin_splunk
Splunk Employee
Splunk Employee

Hi @crizelle, the logic here is not specific to the InfoSec app but applies to many other dashboards you see in Splunk:

  • Malware events come into Splunk with time stamps
  • When you look at the Malware dashboard, it displays events in the past 24 hours by default but you can select a different time window (see screenshot below)
  • If your anti-malware tool does not keep reporting on old malware events, the events will not show in the new time window

InfoSec app: Malware dashboard

Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...