Splunk Enterprise Security

Splunk ES logs

Stanley_Learn
Loves-to-Learn Lots

How can I retrieve the file name was uploaded/shared in any collaboration tool excluding the ones generating by the app? And how to search when someone join a meeting for any collaboration tools?

Labels (1)
0 Karma

Stanley_Learn
Loves-to-Learn Lots

I am trying to create a report of any type of files that are sent in collaboration tools ex: slack or zoom in meeting or in chatbox.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

As @richgalloway said - you need to make sure that you have logs from those solutions in your Splunk instance. Splunk cannot search through the data it doesn't have so first things first - onboard your logs.

Then you have to know how each of those solutions treats file uploads and how it reports them.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The first step is to have your collaboration tools log file transfers to Splunk.  Are they doing that?

---
If this reply helps you, Karma would be appreciated.
0 Karma

Stanley_Learn
Loves-to-Learn Lots

The collaboration logs are transferred to Splunk, it just that when I run my query using Paloalto in Splunk I am getting weird name for file name values, including the file that I was using for testing?
Explain what is zoom-base and zoom-uploading/downloading if anyone can, when I check the event for the file i used there, zoom was not in the event.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Palo Alto is a brand of firewalls (among other things) and has nothing to do directly with zoom, teams or any other of those collab suites.

So if you want to extract such info from the firewall/proxy/any other inspection tool logs, I'm afraid it's between  you and the source of the log. There is alsomthe possibility that your PA simply misinterprets the data and sends the supposed filename wrongly, for example.

It might help if you showed some samples of data (anonymized if needed) and was more specific about what is not working as you assumed it would and how the actual behaviour differs from what you expected.

Let us help yourself. You could have written all this in the first message and save us all time.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

OK, you have to help us in here. You posted this in Enterprise Security section, you called the thread "ES logs" yet you're speaking about some meetings and collaboration tools. What do you actually want to do and what does it have to do specifically with ES?

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...