Alerting

List of common related security alerts

mcoleman2
Explorer

Is there a list of common security related alerts somewhere? Like a cheat sheet of security alerts on various types of servers. I know there's the Enterprise Security app, but it's too expensive for us.

Alerts like: multiple failed login attempts in a short period of time, an abnormal spike in traffic on a webserver, registry changes in windows machines, etc

Tags (1)
0 Karma

AndySplunks
Communicator

There isn't a specific list I've seen anywhere. I've found the generic alerts in Enterprise Security to be mostly useless. Your IDS / IPS or the native systems should be handling a fair majority of those use cases.

What sorts of systems are you sending to Splunk?

Example Use Cases For Windows:
- Who can modify user accounts? Alert if anyone else does it.
- Are there any accounts being used that don't match your naming standards?
- Are there any accounts of a specific standard behaving differently? For example, is a server account logging in to an endpoint?
- List item

0 Karma

mcoleman2
Explorer

I'm sending Windows and Linux logs to Splunk.

0 Karma

AndySplunks
Communicator

Linux is a little tougher. I've yet to find too many good alerts.

This site, Malware Archaeology, has amazing resources for monitoring Windows systems via Splunk. I've implemented a fair number of their use cases.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...