Splunk Search

sysmon and Defender search

Pere
New Member

Hi,

I am quite new to Splunk, so sorry in advance if I ask silly questions.

I have below task to do: "The logs show that Windows Defender has detected a Trojan on one of the machines on the ComTech network. Find the relevant alerts and investigate the logs." I keep searching but dont get the right logs. I seached below filters: 
source="XmlWinEventLog:Microsoft-Windows-Sysmon/Operational"

source="XmlWinEventLog:Microsoft-Windows-Windows Defender/Operational"

I would really appreciate if you could help.

Thanks,

Pere

 

 

Labels (1)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

This is a Splunk forum, not a security analyst forum.  No one knows what data is in your sources.  Very few has expertise in the exact domain you work from.  If you know what data will get the answer you are asked but have difficulty get the result you wanted, illustrate the data and desired results, then explain the logic between the two without SPL.  Volunteers can help you from there.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...