Security

How to Splunk Data Sentinel SIEM Migration

Dom
New Member

| 나머지 splunk_server=로컬 개수=0 /services/saved/searches | 검색 비활성화=0 | 표 제목,검색,*

 

Splunk Web Search 쿼리를 사용하여 Json File을 사용하는 경우

Splunk Cloud의 경우 12개 규칙 Splunk Enterprise의 경우 8개 규칙을 확인했습니다.

내부 데이터 값이 없으면 Sentinel에서 규칙 구성이 존재하도록 하겠습니다.

위 쿼리문을 사용하여 확인하는 샘플 데이터가 있는지도 함께 문의드립니다.

Labels (6)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...