Alerting

ALerts

isin67
New Member

1.  Hi.. i would like to know  what types of alerts can be created using splunk ?

2.  how do i found that fingerprint login generates an event and how to log that event into splunk?

3.  how to make password alert for a website or particular app

Labels (1)
0 Karma

gcusello
Legend

Hi @isin67,

Your questions are just a little not so defined!

Anyway, about the first question, on Splunk you can create every kind of alert: missing of a message or a system, presence of a message, you can define thresholds, etc...

in few words, you have only to exactly define your alerts requirements and using Splunk you can realize them.

Then you can generate the action you like: eMail, script execution, list, etc...

About the second question, you have to define where the authentication messages are generated, how to identify them and how to take them: e.g. in windows:

  • the login events are stored in WinEventLog,
  • they are defined with the EventCode (Login 4624, LogFail 4625, Logout 4634),
  • you can take them using the Splunk Technical Add-On for Windows.

The third answer is the same of the second, you have to define where the authentication messages are generated, how to identify them and how to take them.

I think that you should follow some Splunk training to better understand how Splunk works, you could start from:

Then on YouTube you can find many introductive to Splunk videos.

If you could share more details, I could help you more.

Ciao.

Giuseppe

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!