Splunk Enterprise Security

How to know all the Contents created from a specific data model in Splunk Enterprise Security ?

zacksoft_wf
Contributor

I want to list all the 'Authentication' related content we have created in the ES App.
Is there any SPL query to get this.
Need to list all the dashboards, Notable Events etc... of Authentication type.
I would really appreciate any help.


Labels (1)
0 Karma
1 Solution

dwickram
Explorer

@zacksoft_wf  If you already know your sourcetypes, try follow this post - this may help you to get the relevant KOs : https://community.splunk.com/t5/Security/Sourcetypes-list-of-where-they-re-being-used/m-p/306682

Keen to know how you go with this. 

View solution in original post

Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

I don't think so. Remember that you can reference objects using macros so even if you listed all configuration and user content and searched through it for your data model, you wouldn't find occurences of macros defined with that datamodel. And that could possibly involve another macro. And so on.

So there can be some approximate methods but I don't see a 100% reliable way.

0 Karma

zacksoft_wf
Contributor

@PickleRick   hmm.. That makes sense. thanks for the input.

0 Karma

dwickram
Explorer

@zacksoft_wf  Hi there, not sure if just one SPL can give all the stats you're after, but if you navigate to Configure --> Content Management -->  And on Search window type "Authentication", this gives a list of items configured under Authentication. Did you try this already OR you need still need a SPL to query a statistical view? 

0 Karma

zacksoft_wf
Contributor

SPL query with statistical view would be helpful.

0 Karma

zacksoft_wf
Contributor

I was thinking , if I have my sourcetypes names with me, Can we build a query that can scan _internal log or something and tell me in which contents (dashboard, Correlation Searches etc, ) this sourcetype is used . That could help too.

0 Karma

dwickram
Explorer

@zacksoft_wf  If you already know your sourcetypes, try follow this post - this may help you to get the relevant KOs : https://community.splunk.com/t5/Security/Sourcetypes-list-of-where-they-re-being-used/m-p/306682

Keen to know how you go with this. 

Tags (1)
0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...