Splunk Search

What's the best way to search for a list of MD5?

SupD0cTr
Engager

Where can I find User Instructions for searching for a block of hashes on a regular basis, and emailing an alert if any one of them are detected?

Labels (1)
Tags (1)
0 Karma

Stefanie
Builder

Add your hashes into a csv and create a lookup from it. 

Then your query would be something like: 

index=(your index) .... [|inputlookup md5s.csv ...]  ...

with the "..." being your refining criteria for your search.

 

 

0 Karma
Get Updates on the Splunk Community!

Industry Solutions for Supply Chain and OT, Amazon Use Cases, Plus More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...