Splunk Search

How to query for basic malware outbreak?

Deeksha
New Member

I need a query for basic malware outbreak

Deeksha_0-1671675972843.png

 

Need query with server IP and server name from this raw logs.

Labels (1)
0 Karma

yottanat2021
Explorer

you have to install ta-windows for extract fields and use field to query

search example:
index=* source="WinEventLog:Security" | table _time src src_ip dest action app signature

0 Karma

Deeksha
New Member

Thanks for your reply, but we are using Trend Micro Apex One as an antivirus and we are able to extracting from the same.

Could you please confirm that TA for Microsoft Windows Defender will support Trend Micro Apex One?

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...