Splunk Enterprise

Capture_hostname

Pantman
Observer

I used the query index="botsv2" Amber. I found a capture_hostname: matar 

Pantman_0-1701263405965.pngPantman_1-1701263418745.png

 

Which e-mail seems to be linked to "matar"?

 

And who sends the person attach to the "feed" email to?

 

This is from https://github.com/splunk/botsv2

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...