Splunk Search

What is an SPL search query for detection of stolen credentials?

Hurricanet
Observer

totally stuck with this query 

Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

And what is your problem? What are you trying to achieve? What do you have so far and in what way it's not (yet) what you need?

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...