Splunk Enterprise Security

[Splunk Content] Xp_cmdshell enablement rule error in content management

nooproblems
New Member

On Splunk ES I’m having an issue with the rule “Windows SQL Server xp_cmdshell Config Change” (https://research.splunk.com/endpoint/5eb76fe2-a869-4865-8c4c-8cff424b18b1/).
After enabling it, I can no longer disable or delete the rule.

I created a custom rule equivalent to that one with the search:
index=wineventlog EventCode=15457 "*xp_cmdshell*"
and it encounters the same issue. Even when I manually run the search
index=wineventlog EventCode=15457 "*xp_cmdshell*",
Splunk reports an error. I’m not sure what the underlying issue is. I’m wondering if anyone has encountered this problem before.

Please help me disable or delete this rule, and let me know what the root cause of the issue might be.

nooproblems_0-1764258932428.png

nooproblems_1-1764258964171.png

 

 

Tags (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @nooproblems 

It seems there is something odd going on with the response received from the API call to disable the rule, can you open the browser's Developer Console and click the Network tab, then try the disable action and see if you see a non-200 status API call, if you click in the Response tab is there anything which indicates what could be going on? 

It could be a coincidence that its since enabling this rule (but not necessarily!) but the output from the API call would be helpful in determining the issue.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...