Security

Using Splunk to replace manual viewing of security logs

ryjones13
New Member

Good Morning-

We currently have Splunk installed in house but not overly configured. Each week, I take a our security logs using the MS dumpel command, and compile the 92 logs into one 2 GB text file, run that through a MS Access Database, to kick out a series of critical event logs to review as part of the company I work for's company information security policy and practice of which we have to report to the SEC for Sarbanes-Oxley compliancy. I'm hoping to be able to set up alerts in Splunk to email if certain criteria are found and kick those alerts into our Sharepoint environment to act as a log for this instead. Any advice on configuring alerts like this would be greatly appreciated.

Thanks-

--Ryan

0 Karma

Matthias_BY
Communicator

Hello Ryan,

if i did understand your archtiecture correctly i would suggest you to send all MS Events into Splunk... from there you can classify them with tags or extract some fields and create reports + alerts.

then you can decide if you want to have a report which is sent as PDF regulary to a mailbox which stores it on a sharepoint or you can use alerts who trigger a command. via the command you can give also parameters and trigger a script what might generate something on your sharepoint...

maybe if you have something with access databases and you want to keep those, have a look to the DB Connect App which can pull and push information via JDBC.

br
matthias

martin_mueller
SplunkTrust
SplunkTrust

That sounds a lot like a use case for the http://splunk-base.splunk.com/apps/22297/splunk-app-for-enterprise-security

You can define additional criteria to match your specific requirements to automatically have Splunk generate events for your team to review.

martin_mueller
SplunkTrust
SplunkTrust

It's only available for purchase to Enterprise customers, so you'd have to upgrade your splunk license as well. That's a good idea either way though 🙂

Critically, you cannot define alerts in the free version.

0 Karma

ryjones13
New Member

That looks like it would work but we use the free version, not the Enterprise one. Can I pay for just this app? Or are there notices I can configure within the system?

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...