Splunk Enterprise Security

Splunk Enterprise Security: How to become adept at correlation searches and notable events?

test_qweqwe
Builder

Hello, I have already written similar questions in past, but now it's global issue.
Official documentation not answer to all my questions.

So, let's start!
For example, when I wrote my custom correlation search and created notable event.
Many times it's looks like this or like this.

How me make it look nice and informative?

0 Karma

mdessus_splunk
Splunk Employee
Splunk Employee

Hi, you need to have the relevant fields as output of your rule. For example if your look to some rules in ES, you might find things like this:

... | stats max(_time) as "lastTime",latest(_raw) as "orig_raw",values(result) as "signature",values(src) as "src",values(dest) as "dest",count by "src_user","user" ...

Feel free to post the search you're working on if you need more details.

Get Updates on the Splunk Community!

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...