Splunk Search

How to query for basic malware outbreak?

Deeksha
New Member

I need a query for basic malware outbreak

Deeksha_0-1671675972843.png

 

Need query with server IP and server name from this raw logs.

Labels (1)
0 Karma

yottanat2021
Explorer

you have to install ta-windows for extract fields and use field to query

search example:
index=* source="WinEventLog:Security" | table _time src src_ip dest action app signature

0 Karma

Deeksha
New Member

Thanks for your reply, but we are using Trend Micro Apex One as an antivirus and we are able to extracting from the same.

Could you please confirm that TA for Microsoft Windows Defender will support Trend Micro Apex One?

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...