Local Tech Repair: Splunk

Pages

Showing posts with label Splunk. Show all posts
Showing posts with label Splunk. Show all posts

Tuesday, July 18, 2017

Information Security Training

Here is some training information for the cyber security analyst may need to know to be effective at monitoring the network of an organization. This is just a stripped down and formatted a little different than some of the other articles that I have written before. Lot of the resources will be the same.

Sunday, October 30, 2016

Splunk Extreme Search - xsCreateDDContext & xsWhere

Splunk has the ability to do some very impressive searches to help with statistical analysis. Some of those functions are not very well documented by Splunk's own internal documentation. I am going to go over a few commands and how they can be used.

Sunday, August 21, 2016

How to create notable events via correlation search/manually in Splunk

One of the main things that you can do with Splunk Enterprise Security is dealing around the Incident Review dashboard. You can customize this to be the most helpful to you when doing threat hunting. One of the ways is to automate your searches to create notable events automatically so that you don't have to continually look for them.