TA-EndpointsWatchlist

Splunk Community

TA-EndpointsWatchlist

TA-EndpointsWatchlist
This application provides an IOC watchlist which allows your analysts to manage list of monitored IOCs in self-service manner. This watchlist can be used to: 1) Enrich other lookups 2) Be used as source for your hunting correlation searches 3) Enrich your notables in Splunk ES See the documentation for more information about using the 'Endpoints Watchlist' dashboard (https://github.com/fkolacek/TA-EndpointsWatchlist/wiki). Audit trail: index=`endpoints_watchlist_index` sourcetype=`users_watchlist_sourcetype` | table _time, mac,, nt_host, operating_system_type, expire, reason, reference | sort -_time
0 topics and 0 replies mentioned TA-EndpointsWatchlist in
Latest Topics
No posts to display.
Latest Replies
No posts to display.
Top Topics
No posts to display.
My Topics
No posts to display.