Splunk Search

correlation search

ALLIACOM
New Member

hello every body ,

How to search to correlate there use case please :

Detection of access to basic hash files passwords,
connections from multiple IPs to the same accounts,
Unauthorized device on the network,
Logs deleted from source
Please ?

I want a request in the general framework and I will try to adapt my data.

Thank in advance.

Tags (1)
0 Karma

mstjohn_splunk
Splunk Employee
Splunk Employee

Thanks for posting. Could you give us some more context for your query? You have a much better chance of getting your question answered if you provide more information about your issue. Plus, it will help guide future community users who are facing a similar problem.

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...