Deployment Architecture

Splunk Fish Bucket indicating Virus

indra_wijaya
Engager

Hi Guys,

I have a problem related to Splunk Fishbucket..
When I run my full scan on Splunk server, it found a Trojan on the fishbucket folder.
C:\Program Files\Splunk\var\lib\splunk\fishbucket\4069420869.tmp

Any idea why this is indicated as a Virus?

Tags (1)
0 Karma
1 Solution

adamw
Communicator

It's likely there used to be a virus with a similar file name, ending in tmp. Some AV programs trigger on any tmp file not actually in the Windows tmp/temp folder, but this is likely a false positive.

View solution in original post

indra_wijaya
Engager

Hi adamw,

Thank you for your reply.. So this is just a false positive alert.. I see then.. Thank you for your response..

0 Karma

adamw
Communicator

It's likely there used to be a virus with a similar file name, ending in tmp. Some AV programs trigger on any tmp file not actually in the Windows tmp/temp folder, but this is likely a false positive.

Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...