attack_data icon indicating copy to clipboard operation
attack_data copied to clipboard

how do I make splunk es to check my uploaded logs

Open maybe-why-not opened this issue 1 year ago • 1 comments

I have installed splunk es app and uploaded botsv1.stream_http.json image but incident_review and ess_security_posture is not hitting any event image how do I make splunk es to check my uploaded logs and generate a list of alerts like below. Please note that I am not checking the logs forwarded by agent, but the log files uploaded on the browser side image thank you

maybe-why-not avatar Jun 05 '24 10:06 maybe-why-not

The BOTS sample data is a single moment in time. So you need to ensure your ES Correlation searches are reviewing events for that time period.

TheLawsOfChaos avatar Oct 12 '24 18:10 TheLawsOfChaos