- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Help me with the SPL
Akhanda
Loves-to-Learn Everything
03-04-2024
02:28 AM
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ITWhisperer

SplunkTrust
03-04-2024
02:42 AM
I am not sure what that ask is here
What is your concern regarding plagarism? If I rewrite this SPL and you use it, are you then not plagarising my SPL?
It is not clear what NTLM (type 3) is - could you just change the Logon_Type or LogonType part of the search to look for 3 instead of 10?
Please share some anonymised events so we can see what you are dealing with, and an indication of the expected output?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Akhanda
Loves-to-Learn Everything
03-04-2024
04:36 AM
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Akhanda
Loves-to-Learn Everything
03-05-2024
05:44 AM
This above query is based on
https://www.splunk.com/en_us/blog/security/active-directory-lateral-movement-detection-threat-resear...
if possible pls help me in making a query as per the sample event.
thanks
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ITWhisperer

SplunkTrust
03-05-2024
07:10 AM
Sorry, I am not a security expert.
