04.10.2015 Views

Security Jiujitsu

conf2015_DVeuve_Splunk_SecurityCompliance_SecurityJiujitsuBuildingCorrelation

conf2015_DVeuve_Splunk_SecurityCompliance_SecurityJiujitsuBuildingCorrelation

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Techniques – Common InformaEon Model <br />

tag=authenEcaEon | chart count over src by acEon | where success>0 AND <br />

failure>10 <br />

If you leverage Splunk’s Common InformaEon Model you can write one <br />

search across many products. <br />

The above search could cover twenty different products, all with matching <br />

field extracEons <br />

Most searches in this session will be based on the common <br />

informaEon model <br />

Try with the ES Sandbox! <br />

16

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!