Monitoring Splunk

Splunk log4j

revanthammineni
Path Finder

Hello Splunkers,

I’ve created a search to show up all the log4j related events by looking into the strings. We are trying to dig into the events and schedule an alert.

Are there any particular messages we should check in the events for log4j vulnerability? Any particular events that has high risk factor? 

thanks in advance. 

Labels (2)
Tags (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
There are examples and discussions on Splunk Slack on channel #log4jstuff.
0 Karma

revanthammineni
Path Finder

Thanks for the quick response.
Could you send me the link to this channel. I couldn’t seem to find it.

Also, If you have any documents regards to my question, Please send them over. TIA

0 Karma
Get Updates on the Splunk Community!

Explore the Latest Educational Offerings from Splunk

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

Meet Duke Cyberwalker | A hero’s journey with Splunk

We like to say, the lightsaber is to Luke as Splunk is to Duke. Curious yet? Then read Eric Fusilero’s latest ...

The Future of Splunk Search is Here - See What’s New!

We’re excited to introduce two powerful new search features, now generally available for Splunk Cloud Platform ...