How can I retrieve the file name was uploaded/shared in any collaboration tool excluding the ones generating by the app? And how to search when someone join a meeting for any collaboration tools?
I am trying to create a report of any type of files that are sent in collaboration tools ex: slack or zoom in meeting or in chatbox.
As @richgalloway said - you need to make sure that you have logs from those solutions in your Splunk instance. Splunk cannot search through the data it doesn't have so first things first - onboard your logs.
Then you have to know how each of those solutions treats file uploads and how it reports them.
The first step is to have your collaboration tools log file transfers to Splunk. Are they doing that?
The collaboration logs are transferred to Splunk, it just that when I run my query using Paloalto in Splunk I am getting weird name for file name values, including the file that I was using for testing?
Explain what is zoom-base and zoom-uploading/downloading if anyone can, when I check the event for the file i used there, zoom was not in the event.
Palo Alto is a brand of firewalls (among other things) and has nothing to do directly with zoom, teams or any other of those collab suites.
So if you want to extract such info from the firewall/proxy/any other inspection tool logs, I'm afraid it's between you and the source of the log. There is alsomthe possibility that your PA simply misinterprets the data and sends the supposed filename wrongly, for example.
It might help if you showed some samples of data (anonymized if needed) and was more specific about what is not working as you assumed it would and how the actual behaviour differs from what you expected.
Let us help yourself. You could have written all this in the first message and save us all time.
OK, you have to help us in here. You posted this in Enterprise Security section, you called the thread "ES logs" yet you're speaking about some meetings and collaboration tools. What do you actually want to do and what does it have to do specifically with ES?