Splunk Search

Basic Query help

mnmn777
Observer

I just want to look for a hash signature in Splunk. 

Example: d09a773dab9a20e6b39176e9cf76ac6863fe388d69367407c317c71652c84b9e

What is the basic query please? 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mnmn777,

sorry but I don't understand your need:

the hash you shared is what you want to search in your logs or what else?

if this is waht you want to search, you can use this string in a simple search:

index=your:index d09a773dab9a20e6b39176e9cf76ac6863fe388d69367407c317c71652c84b9e

if you could add more informations to you question we'd be able to help you.

CIao.

Giuseppe

0 Karma

mnmn777
Observer

I want to see if a file, which has that SHA256 signature is in my Enterprise or logs. 

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @mnmn777,

If you have in your logs the SHA of many files, you can use Splunk to search that signature, which data have you to search?

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...