Despite the number of links:
https://www.splunk.com/blog/2018/05/25/boss-of-the-soc-bots-investigation-workshop-for-splunk.html
One first installs the app:
https://splunkbase.splunk.com/app/3985/
You are then directed to Copy/Move the entire extracted BOTS directory into the $SPLUNK_HOME/etc/apps directory.
How can I find the exact path for my own environment? This directory does not appear to exist.
and secondly the dataset:
http://explore.splunk.com/BOTS_1_0_datasets
For which you must register. It will take you to a GitHub link. Then what?
... View more
I guess at this point, it would be useful in getting your insight.
If you want to understand a new splunk environment, what are things you look for? What searches do you generally perform?
index=* | stats values(index)
sourcetype=* |stats values(sourcetype)
What else?
... View more
If you were to query the following:
the total number of quarantined files for a particular End point software
What does that translate to you syntax wise?
... View more