Splunk Search

correlation search

ALLIACOM
New Member

hello every body ,

How to search to correlate there use case please :

Detection of access to basic hash files passwords,
connections from multiple IPs to the same accounts,
Unauthorized device on the network,
Logs deleted from source
Please ?

I want a request in the general framework and I will try to adapt my data.

Thank in advance.

Tags (1)
0 Karma

mstjohn_splunk
Splunk Employee
Splunk Employee

Thanks for posting. Could you give us some more context for your query? You have a much better chance of getting your question answered if you provide more information about your issue. Plus, it will help guide future community users who are facing a similar problem.

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...