Splunk Enterprise Security

[Splunk Content] Xp_cmdshell enablement rule error in content management

nooproblems
New Member

On Splunk ES I’m having an issue with the rule “Windows SQL Server xp_cmdshell Config Change” (https://research.splunk.com/endpoint/5eb76fe2-a869-4865-8c4c-8cff424b18b1/).
After enabling it, I can no longer disable or delete the rule.

I created a custom rule equivalent to that one with the search:
index=wineventlog EventCode=15457 "*xp_cmdshell*"
and it encounters the same issue. Even when I manually run the search
index=wineventlog EventCode=15457 "*xp_cmdshell*",
Splunk reports an error. I’m not sure what the underlying issue is. I’m wondering if anyone has encountered this problem before.

Please help me disable or delete this rule, and let me know what the root cause of the issue might be.

nooproblems_0-1764258932428.png

nooproblems_1-1764258964171.png

 

 

Tags (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @nooproblems 

It seems there is something odd going on with the response received from the API call to disable the rule, can you open the browser's Developer Console and click the Network tab, then try the disable action and see if you see a non-200 status API call, if you click in the Response tab is there anything which indicates what could be going on? 

It could be a coincidence that its since enabling this rule (but not necessarily!) but the output from the API call would be helpful in determining the issue.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

From Raw Data to Executive-Ready Stories, Faster

Build Data Stories for Every Audience  A dashboard is rarely just a dashboard. It might be the view an ...

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...