-
Recent Posts
Recent Comments
Elastic 8.x custom C… on Retrieve http_ca key in Elasti… xli14 on Cyberark PVWA issue – ob… xli14 on splunk arin lookup xli14 on softwarefeature National ASL Service… on Splunk Indexer — indexan… Archives
- February 2024
- April 2023
- February 2023
- January 2023
- October 2022
- July 2022
- June 2022
- March 2022
- October 2021
- February 2021
- December 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- October 2019
- September 2019
- August 2019
- June 2019
- May 2019
- March 2019
- November 2018
- October 2018
- September 2018
- August 2018
- July 2018
- June 2018
- May 2018
- April 2018
- March 2018
- February 2018
- January 2018
- November 2017
- October 2017
- August 2017
- June 2017
- May 2017
- April 2017
- March 2017
- February 2017
- January 2017
- December 2016
- November 2016
- October 2016
- September 2016
- November 2015
- October 2015
- September 2015
- August 2015
- July 2015
- June 2015
- May 2015
- April 2015
- July 2014
- February 2014
- November 2013
- January 2013
- May 2012
- April 2012
- March 2012
- February 2012
- January 2012
- September 2011
- March 2011
- January 2011
- November 2010
- September 2010
- August 2010
- July 2010
- June 2010
- May 2010
- April 2010
- March 2010
- February 2010
- January 2010
- December 2009
- November 2009
- October 2009
- September 2009
- August 2009
- July 2009
- June 2009
- May 2009
- April 2009
- March 2009
- February 2009
- January 2009
- December 2008
- November 2008
- October 2008
- September 2008
- August 2008
- July 2008
- May 2008
- April 2008
- March 2008
- February 2008
- January 2008
- December 2007
- November 2007
- January 2006
Categories
- AMC10
- ansible
- AWS
- azure
- certificate
- cyberark
- 电器
- English
- 钓鱼
- 计算机与 Internet
- forensic
- Fortinet
- HAVC
- house
- Kaili
- ldap
- mysql authentication
- Network
- nginx
- nmap
- OSSEC
- PaloAlto
- PCI
- powershell
- Python
- radius
- rapid7
- regex
- saml
- security
- sentinel
- shell
- snmp
- splunk
- TCPIP
- Uncategorized
- WAF
- web
- Windows
- wordpress
- zabbix
- zscaler
- 健康与保健
- 娱乐
- 安全
- 少儿
- 汽车
Meta
Category Archives: splunk
Splunk SAML integration with AAD
Here is the article for reference. https://www.splunk.com/en_us/blog/cloud/configuring-microsoft-s-azure-security-assertion-markup-language-saml-single-sign-on-sso-with-splunk-cloud-azure-portal.html For object ID referenced herein, this is the connection between Azure AD and splunk. When do the saml authentication, ID Service (Splunk) will get all groups of a users through group claims, if … Continue reading
Posted in saml, splunk
Leave a comment
splunk cmdlet
Check Splunk Env: /opt/splunk/bin/splunk cmd python -c “import os; print(os.environ)” Reload Splunk App: /opt/splunk/bin/splunk _internal call /services/apps/local/splunk_app_db_connect/_reload list users and roles: | rest /services/authentication/users | table title realname roles type email List current logon users: | rest /services/authentication/current-context | table … Continue reading
Splunk filter AD computer authentication events
We have a local splunk environment almost reaching our license threshold. One option is to filter unnecessary event. Previous we have filtered some windows EventID ( backlist ), but now windows Events still is one of the big volume, among … Continue reading
Ingest Azure NSG flow into splunk
Recently for troubleshooting purpose, I need to import the NSG flow logs to splunk for easy search and troubleshoot, though azure network watcher is a traffic analytic tool, I still don’t know much how to use it, for example, to … Continue reading
Posted in splunk, Uncategorized
Leave a comment
No Log on Splunk
This happened at least twice. Normally you data indexed in splunk server, all of a sudden, some log is missing and splunk alert comes “No data from some host for last 1 hour”. Nothing changed for the environment. One time, … Continue reading
Posted in splunk
Leave a comment
Splunk – Summary index
Enable summary index for the search ( index=”index” | stats count by dest_hostname | collect index=summary_index_test ) every hour. The effect is huge: no sumary search takes about 1 minute for last 4 hours statistics summary index … Continue reading
Posted in splunk
Leave a comment
Splunk – bucket lexicons and segmentation – save storage
Splunk – bucket lexicons and segmentation About Segmentation Event segmentation is an operation key to how Splunk processes your data as it is being both indexed and searched. At index time, the segmentation configuration determines what rules Splunk uses to extract … Continue reading
splunk cmd walklex
splunk cmd walklex some_tsindx_file.tsidx “” # ll rawdata/ total 110384 -rw——- 1 splunk splunk 85337 Jun 21 15:38 1179739938 -rw——- 1 splunk splunk 112649873 Jun 21 15:38 journal.gz -rw——- 1 splunk splunk 285066 Jun 21 15:38 slicesv2.dat # pwd /opt/splunk/var/lib/splunk/fortinet/db/hot_v1_8685 … Continue reading
splunk tstats –> much faster than stats on indexed fields
http://docs.splunk.com/Documentation/Splunk/7.1.1/SearchReference/Tstats tstats Description Use the tstats command to perform statistical queries on indexed fields in tsidx files. The indexed fields can be from normal index data, tscollect data, or accelerated data models. Syntax | tstats [prestats=<bool>] [local=<bool>] [append=<bool>] [summariesonly=<bool>] [allow_old_summaries=<bool>] [chunk_size=<unsigned int>] <stats-func>… [FROM … Continue reading
Splunk Event Segmentation
Segmentation breaks events up into searchable segments at index time, and again at search time. Segments can be classified as MAJOR or MINOR. Minor segments are breaks within Major segments. For example, IP address “192.1.2.3” is a major segment, … Continue reading
Posted in splunk
Leave a comment