Getting Data In

Splunk query to find systems with wireshark installed

lexesco99
Engager

Is there a way to use Splunk to find out if wireshark is installed on any of the systems? Is there a query for this

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

In order to search for something in Splunk ("query" the data as you said) you must first have the data from which you want to search ingested into Splunk.

So if you have such data (for example from some endpoint inventory software or from installer logs), you will probably be able to find some information about the wireshark.

But the main question is whether you have this data.

Splunk on its own is "just" an data analysis platform. It's not a network monitor, endpoint manager, vulnerability scanner and so on.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

if you have this information on your logs which have ingested into splunk then you can query this information.

  • What logs you have?
  • What platforms those contains?
  • What you have already tried?

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...