...xception
1) if LastAlertedQueue(CSV) is greater than Zero, it should alert once and after alerting once, it shouldn't alert till 00:00 AM. (I am writing results from 1st alert in a CSV file)
2) if C...
Hi,
I am working on creating a use case for changes made in firewall configuration. Whenever a firewall admin making changes in a configuration, it should trigger an alert.
sourcetype=f...
When writing a custom search command, modular input, custom REST handler, alert action, or anything running Python in Splunk Enterprise, how can I use a debugger to set breakpoints, step into/over c...
I use the CSV exports of 10-12 search results each month to create an Excel report.
I am manually exporting the results, then saving them in a location on my PC, then running an Excel macro that p...
...ar/log/snort/alert, I see full alerts being generated, but no additional network traffic on tcp port 9997 between the two servers. I do, however, consistently see the heartbeat every few seconds (I t...
What are best practices for how to deploy an add-on such that different servers run the same add-on, but with slightly different configurations? A common situation is when the add-on has different i...
...hantom, I have to manually press the "Send to Phantom" button. Is there a good method to automate this?
The Phantom add-on has an alert action to create an event in Phantom, but the add-on's README says t...