Splunk Search

sysmon and Defender search

Pere
New Member

Hi,

I am quite new to Splunk, so sorry in advance if I ask silly questions.

I have below task to do: "The logs show that Windows Defender has detected a Trojan on one of the machines on the ComTech network. Find the relevant alerts and investigate the logs." I keep searching but dont get the right logs. I seached below filters: 
source="XmlWinEventLog:Microsoft-Windows-Sysmon/Operational"

source="XmlWinEventLog:Microsoft-Windows-Windows Defender/Operational"

I would really appreciate if you could help.

Thanks,

Pere

 

 

Labels (1)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

This is a Splunk forum, not a security analyst forum.  No one knows what data is in your sources.  Very few has expertise in the exact domain you work from.  If you know what data will get the answer you are asked but have difficulty get the result you wanted, illustrate the data and desired results, then explain the logic between the two without SPL.  Volunteers can help you from there.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...