Security

Using Splunk to replace manual viewing of security logs

ryjones13
New Member

Good Morning-

We currently have Splunk installed in house but not overly configured. Each week, I take a our security logs using the MS dumpel command, and compile the 92 logs into one 2 GB text file, run that through a MS Access Database, to kick out a series of critical event logs to review as part of the company I work for's company information security policy and practice of which we have to report to the SEC for Sarbanes-Oxley compliancy. I'm hoping to be able to set up alerts in Splunk to email if certain criteria are found and kick those alerts into our Sharepoint environment to act as a log for this instead. Any advice on configuring alerts like this would be greatly appreciated.

Thanks-

--Ryan

0 Karma

Matthias_BY
Communicator

Hello Ryan,

if i did understand your archtiecture correctly i would suggest you to send all MS Events into Splunk... from there you can classify them with tags or extract some fields and create reports + alerts.

then you can decide if you want to have a report which is sent as PDF regulary to a mailbox which stores it on a sharepoint or you can use alerts who trigger a command. via the command you can give also parameters and trigger a script what might generate something on your sharepoint...

maybe if you have something with access databases and you want to keep those, have a look to the DB Connect App which can pull and push information via JDBC.

br
matthias

martin_mueller
SplunkTrust
SplunkTrust

That sounds a lot like a use case for the http://splunk-base.splunk.com/apps/22297/splunk-app-for-enterprise-security

You can define additional criteria to match your specific requirements to automatically have Splunk generate events for your team to review.

martin_mueller
SplunkTrust
SplunkTrust

It's only available for purchase to Enterprise customers, so you'd have to upgrade your splunk license as well. That's a good idea either way though 🙂

Critically, you cannot define alerts in the free version.

0 Karma

ryjones13
New Member

That looks like it would work but we use the free version, not the Enterprise one. Can I pay for just this app? Or are there notices I can configure within the system?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...