Alerting

List of common related security alerts

mcoleman2
Explorer

Is there a list of common security related alerts somewhere? Like a cheat sheet of security alerts on various types of servers. I know there's the Enterprise Security app, but it's too expensive for us.

Alerts like: multiple failed login attempts in a short period of time, an abnormal spike in traffic on a webserver, registry changes in windows machines, etc

Tags (1)
0 Karma

AndySplunks
Communicator

There isn't a specific list I've seen anywhere. I've found the generic alerts in Enterprise Security to be mostly useless. Your IDS / IPS or the native systems should be handling a fair majority of those use cases.

What sorts of systems are you sending to Splunk?

Example Use Cases For Windows:
- Who can modify user accounts? Alert if anyone else does it.
- Are there any accounts being used that don't match your naming standards?
- Are there any accounts of a specific standard behaving differently? For example, is a server account logging in to an endpoint?
- List item

0 Karma

mcoleman2
Explorer

I'm sending Windows and Linux logs to Splunk.

0 Karma

AndySplunks
Communicator

Linux is a little tougher. I've yet to find too many good alerts.

This site, Malware Archaeology, has amazing resources for monitoring Windows systems via Splunk. I've implemented a fair number of their use cases.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...