Splunk Enterprise Security

How to know the correlation search query and time range conditions for two of these use cases?

Ash
Engager

Please let me know the correlation search query and time range conditions for two of these usecases. I have windows powershell logs onboarded.

 

1. Suspicious Windows Shell Launched by Web Applications 

2. Suspicious Windows Shell Launched by a trusted process

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...