Deployment Architecture

Need assistance on use cases

asm_coe
Explorer

Hello,

I'm new to splunk. Have deployed splunk 7.2.4 on windows 2012.
Can you please suggest me few uses cases which can be done using application logs. Thanks.

Tags (1)
0 Karma

lakshman239
Influencer

You can do a number of use cases - based on your OS and/or applications deployed on it. All boils down to what you need for your organization.

You could look at the following to the list of use cases and you can choose what you need.

https://www.splunk.com/blog/2016/02/03/introducing-splunk-security-use-cases.html

https://www.ultimatewindowssecurity.com/securitylog/quickref/default.aspx - Start with Security log quick reference

https://splunkbase.splunk.com/app/742/ Splunk add on for Windows - to monitor log on attempts, audit changes etc..
https://splunkbase.splunk.com/app/3435/ Security essentials app having a number of use cases.
https://splunkbase.splunk.com/app/3593/ Ransomware detection

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...