Security Jiujitsu
conf2015_DVeuve_Splunk_SecurityCompliance_SecurityJiujitsuBuildingCorrelation
conf2015_DVeuve_Splunk_SecurityCompliance_SecurityJiujitsuBuildingCorrelation
- No tags were found...
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
Techniques – Common InformaEon Model <br />
tag=authenEcaEon | chart count over src by acEon | where success>0 AND <br />
failure>10 <br />
If you leverage Splunk’s Common InformaEon Model you can write one <br />
search across many products. <br />
The above search could cover twenty different products, all with matching <br />
field extracEons <br />
Most searches in this session will be based on the common <br />
informaEon model <br />
Try with the ES Sandbox! <br />
16