Expertise Needed for Undetermined Splunk Project
Budget: $30 – $250 USD
Hello;
Please i need some help in creating some basic splunk query. This shouldn't be a complex task for you and you just need to create a queery for me which alings with the indexes and sourcetypes of my choice, so i can integrate well with my envrionment.
I will neeed splunk queries to be created for the below 6 use cases;
1. Splunk query for - Identifying DNS resolutions performed by endpoint (DNS)
2. Splunk query for - Identifying the assigned IP address of the endpoint at the time of the activity that generate the incident (Datasoucre to be used in query include -pan_logs - GP, DHCP logs)
3. Splunk query for - Identifying downloaded files for the endpoint (Datasoucre to be used in query include - pan_logs, Netskope, CB Response file mods)
4. Splunk query for - Identifying email messages received by the affected user from external sources including IOC/attachment information.
5. Splunk query for - Identifying when malware was first seen in the environment. (Looking for first event with malware hash or name - proofpoint, netskope, pan_logs, cbresponse, cbprotect, mcafee )
6. Splunk query for - Identifying 3rd party email use?
Please let me know if you have any questions.
Thanks
Please i need some help in creating some basic splunk query. This shouldn't be a complex task for you and you just need to create a queery for me which alings with the indexes and sourcetypes of my choice, so i can integrate well with my envrionment.
I will neeed splunk queries to be created for the below 6 use cases;
1. Splunk query for - Identifying DNS resolutions performed by endpoint (DNS)
2. Splunk query for - Identifying the assigned IP address of the endpoint at the time of the activity that generate the incident (Datasoucre to be used in query include -pan_logs - GP, DHCP logs)
3. Splunk query for - Identifying downloaded files for the endpoint (Datasoucre to be used in query include - pan_logs, Netskope, CB Response file mods)
4. Splunk query for - Identifying email messages received by the affected user from external sources including IOC/attachment information.
5. Splunk query for - Identifying when malware was first seen in the environment. (Looking for first event with malware hash or name - proofpoint, netskope, pan_logs, cbresponse, cbprotect, mcafee )
6. Splunk query for - Identifying 3rd party email use?
Please let me know if you have any questions.
Thanks