We have a portal that is used by the SOC for malware investigations. The portal has the ability to login to Splunk & conduct searches.
How can I generalise the search to match the particular event. For example:
Source IP: A.B.C.D
Target IP: D.E.F.G
Date & Time: 22/02/2017 14:00
Our aim is to pull the specific event from Splunk.
The IP & date/time will change for each event.
... View more