Splunk Enterprise Security

[Splunk Content] Xp_cmdshell enablement rule error in content management

nooproblems
New Member

On Splunk ES I’m having an issue with the rule “Windows SQL Server xp_cmdshell Config Change” (https://research.splunk.com/endpoint/5eb76fe2-a869-4865-8c4c-8cff424b18b1/).
After enabling it, I can no longer disable or delete the rule.

I created a custom rule equivalent to that one with the search:
index=wineventlog EventCode=15457 "*xp_cmdshell*"
and it encounters the same issue. Even when I manually run the search
index=wineventlog EventCode=15457 "*xp_cmdshell*",
Splunk reports an error. I’m not sure what the underlying issue is. I’m wondering if anyone has encountered this problem before.

Please help me disable or delete this rule, and let me know what the root cause of the issue might be.

nooproblems_0-1764258932428.png

nooproblems_1-1764258964171.png

 

 

Tags (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @nooproblems 

It seems there is something odd going on with the response received from the API call to disable the rule, can you open the browser's Developer Console and click the Network tab, then try the disable action and see if you see a non-200 status API call, if you click in the Response tab is there anything which indicates what could be going on? 

It could be a coincidence that its since enabling this rule (but not necessarily!) but the output from the API call would be helpful in determining the issue.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...