Splunk Search

What's the best way to search for a list of MD5?

SupD0cTr
Engager

Where can I find User Instructions for searching for a block of hashes on a regular basis, and emailing an alert if any one of them are detected?

Tags (1)
0 Karma

Stefanie
Builder

Add your hashes into a csv and create a lookup from it. 

Then your query would be something like: 

index=(your index) .... [|inputlookup md5s.csv ...]  ...

with the "..." being your refining criteria for your search.

 

 

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...