Splunk Enterprise

Warning User when try to execute outoutlook up command from front end to avoid deleteing accidental records from kvstore

vksplunk1
Explorer

Hi  -  Is there a way to Warning the user when try to execute outoutlook up command from front end to avoid deleting accidental records from kvstore.

 

Thank you

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @vksplunk1 

Outputlookup is already categorised as a risky command in terms of protection against SPL in links clicked, or in dashboard ("In the Search app, the warning dialog box appears when you click a link or type a URL that loads a search which contains risky commands. In dashboards, the warning dialog box appears automatically unless an input or visualization contains a search with a risky command") however it is not currently possible to display the alert if a user just types it out themselves into the search bar.
Check out https://docs.splunk.com/Documentation/Splunk/9.4.0/Security/SPLsafeguards for more information about this.

 

Please let me know how you get on and consider accepting this answer or adding karma this answer if it has helped.
Regards

Will

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...