Splunk Search

How to query for basic malware outbreak?

Deeksha
New Member

I need a query for basic malware outbreak

Deeksha_0-1671675972843.png

 

Need query with server IP and server name from this raw logs.

Labels (1)
0 Karma

yottanat2021
Explorer

you have to install ta-windows for extract fields and use field to query

search example:
index=* source="WinEventLog:Security" | table _time src src_ip dest action app signature

0 Karma

Deeksha
New Member

Thanks for your reply, but we are using Trend Micro Apex One as an antivirus and we are able to extracting from the same.

Could you please confirm that TA for Microsoft Windows Defender will support Trend Micro Apex One?

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...