Splunk Enterprise Security

Splunk ES logs

Stanley_Learn
Loves-to-Learn Lots

How can I retrieve the file name was uploaded/shared in any collaboration tool excluding the ones generating by the app? And how to search when someone join a meeting for any collaboration tools?

Labels (1)
0 Karma

Stanley_Learn
Loves-to-Learn Lots

I am trying to create a report of any type of files that are sent in collaboration tools ex: slack or zoom in meeting or in chatbox.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

As @richgalloway said - you need to make sure that you have logs from those solutions in your Splunk instance. Splunk cannot search through the data it doesn't have so first things first - onboard your logs.

Then you have to know how each of those solutions treats file uploads and how it reports them.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The first step is to have your collaboration tools log file transfers to Splunk.  Are they doing that?

---
If this reply helps you, Karma would be appreciated.
0 Karma

Stanley_Learn
Loves-to-Learn Lots

The collaboration logs are transferred to Splunk, it just that when I run my query using Paloalto in Splunk I am getting weird name for file name values, including the file that I was using for testing?
Explain what is zoom-base and zoom-uploading/downloading if anyone can, when I check the event for the file i used there, zoom was not in the event.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Palo Alto is a brand of firewalls (among other things) and has nothing to do directly with zoom, teams or any other of those collab suites.

So if you want to extract such info from the firewall/proxy/any other inspection tool logs, I'm afraid it's between  you and the source of the log. There is alsomthe possibility that your PA simply misinterprets the data and sends the supposed filename wrongly, for example.

It might help if you showed some samples of data (anonymized if needed) and was more specific about what is not working as you assumed it would and how the actual behaviour differs from what you expected.

Let us help yourself. You could have written all this in the first message and save us all time.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

OK, you have to help us in here. You posted this in Enterprise Security section, you called the thread "ES logs" yet you're speaking about some meetings and collaboration tools. What do you actually want to do and what does it have to do specifically with ES?

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...