• Search
  • Dashboards
  • Browse
    • Sourcetype

      • _audit
      • _internal
      • access_combined
      • apache
      • audittrail
      • citrix:netscaler:syslog
      • Cron
      • crowdstrike
      • Dashboards
      • datamodels
      • DBConnect
      • Enterprise Security
      • eval
      • F5
      • Fun Stuff & Helpful Hints
      • Hack
      • Hygiene
      • IIS
      • Juniper
      • Linux Performance
      • linux_secure
      • Malware
      • Monitoring
      • Networking
      • opensense
      • opsec
      • osx_secure
      • Perfmon:Available Memory
      • Perfmon:CPU Load
      • Perfmon:Free Disk Space
      • Perfmon:Network Interface
      • postfix_syslog
      • Qualys
      • REST
      • RFQ – Request For Query
      • splunkd
      • Tenable
      • Uncategorized
      • Unix:Uptime
      • WinEventLog:Application
      • WinEventLog:Security
      • WinEventLog:System
      • WinRegistry
      • WMI:Uptime
    • Tags

      6.1.2 admin apache audit audittrail authentication Cisco Diagnostics failed logon Firewall IIS index indexes internal license License usage Linux linux audit Login Logon malware Network Perfmon Performance qualys REST Security sourcetype splunk splunkd splunk on splunk Tenable Tenable Security Center troubleshoot troubleshooting tstats Universal Forwarder users Vulnerabilities Web Traffic Windows Windows Audit Windows Security _audit _internal
  • Post New Query
  • Our Blog
  • Splunk Jobs
  • Search
  • Dashboards
  • Browse
    • Sourcetype

      • _audit
      • _internal
      • access_combined
      • apache
      • audittrail
      • citrix:netscaler:syslog
      • Cron
      • crowdstrike
      • Dashboards
      • datamodels
      • DBConnect
      • Enterprise Security
      • eval
      • F5
      • Fun Stuff & Helpful Hints
      • Hack
      • Hygiene
      • IIS
      • Juniper
      • Linux Performance
      • linux_secure
      • Malware
      • Monitoring
      • Networking
      • opensense
      • opsec
      • osx_secure
      • Perfmon:Available Memory
      • Perfmon:CPU Load
      • Perfmon:Free Disk Space
      • Perfmon:Network Interface
      • postfix_syslog
      • Qualys
      • REST
      • RFQ – Request For Query
      • splunkd
      • Tenable
      • Uncategorized
      • Unix:Uptime
      • WinEventLog:Application
      • WinEventLog:Security
      • WinEventLog:System
      • WinRegistry
      • WMI:Uptime
    • Tags

      6.1.2 admin apache audit audittrail authentication Cisco Diagnostics failed logon Firewall IIS index indexes internal license License usage Linux linux audit Login Logon malware Network Perfmon Performance qualys REST Security sourcetype splunk splunkd splunk on splunk Tenable Tenable Security Center troubleshoot troubleshooting tstats Universal Forwarder users Vulnerabilities Web Traffic Windows Windows Audit Windows Security _audit _internal
  • Post New Query
  • Our Blog
  • Splunk Jobs

Members

Profile picture of Opeyemi Olatunji

Opeyemi Olatunji

@opeolat Active 5 years, 2 months ago
  • Activity
  • Profile
  • Posts
  • Personal
  • Mentions
  • Favorites
  • Profile picture of Opeyemi Olatunji
    5 years, 2 months ago

    Opeyemi Olatunji wrote a new post

    index=_audit sourcetype=”incident_review”
    | table rule_name comment status
    | rename rule_name as “Notable Event” comment as “Closing Comment” status as Status
    | eval Status=if(Status=5,”Closed”,if(Status=2,”In […]

  • Profile picture of Opeyemi Olatunji
    5 years, 2 months ago

    Opeyemi Olatunji wrote a new post

    Helps to investigate authentications through CISCO_ISE device. This identifies who logs in, the MAC address and IP for any use cases
    index= “”
    |rex field=”cisco_av_pair” […]

  • Profile picture of Opeyemi Olatunji
    5 years, 2 months ago

    Opeyemi Olatunji wrote a new post

    Investigate an IP through Palo Alto Logsindex= |stats c sum(bytes) as Bytes_Out by _time user application action dest_ip dest_location src_ip client_ip client_location session_end_reason […]

  • Profile picture of Opeyemi Olatunji
    5 years, 2 months ago

    Opeyemi Olatunji wrote a new post

    index=_internal sourcetype=splunkd “deployment_client”
    |stats latest(_time) as LatestReportTime values(server_name) as Server_Name by host |convert ctime(LatestReportTime) |rename host as Host
    |fields + Host […]

  • Profile picture of Opeyemi Olatunji
    5 years, 2 months ago

    Opeyemi Olatunji wrote a new post

    |rest /servicesNS/-/-/saved/searches |table search title description alert_type “alert.expires” “alert.suppress” “alert.suppress.fields”
    |search alert_type=”always”
    |fillnull value=0 […]

  • Profile picture of Opeyemi Olatunji
    5 years, 2 months ago

    Opeyemi Olatunji's profile was updated

  • Profile picture of Opeyemi Olatunji
    5 years, 4 months ago

    Opeyemi Olatunji wrote a new post

    `notable`
    | stats latest(lastTime) as LastTimeSeen values(rule_name) as “Rule Name” values(comment) as “Historical Analysis” values(user) as User by _time event_id, urgency
    | eval LastTimeSeen=strftime(LastTimeSeen,”%+”)

  • Profile picture of Opeyemi Olatunji
    5 years, 4 months ago

    Opeyemi Olatunji wrote a new post

    |datamodel

    |rex field=_raw “”description”:”(?w+|w+s+w+|w+s+w+s+w+|w+s+w+s+w+s+w+s+w+|w+s+w+s+w+s+w+s+w+s+w+|w+s+w+s+w+s+w+s+w+s+w+s+w+)”,”

    |rex field=_raw […]

  • Profile picture of Opeyemi Olatunji
    5 years, 4 months ago

    opeolat became a registered member

  • Profile picture of Opeyemi Olatunji
    5 years, 4 months ago

    Opeyemi Olatunji became a registered member

  • Home
  • Log In
  • Register
  • About GoSplunk
  • GoSplunk FAQs
  • Contact the GoSplunk Team
  • Splunk Website
  • Splunk Documentation
  • Splunk Answers

GoSplunk is not affiliated with Splunk Inc. in any way.

© 2019 GoSplunk
  • Privacy Policy
  • Terms and Conditions
  • Forgot Password?
sponsored