Expertise Needed for Undetermined Splunk Project

Job ID: 38169986

Budget: $30 – $250 USD

Hello;

Please i need some help in creating some basic splunk query. This shouldn't be a complex task for you and you just need to create a queery for me which alings with the indexes and sourcetypes of my choice, so i can integrate well with my envrionment.

I will neeed splunk queries to be created for the below 6 use cases;


1. Splunk query for - Identifying DNS resolutions performed by endpoint (DNS)

2. Splunk query for - Identifying the assigned IP address of the endpoint at the time of the activity that generate the incident (Datasoucre to be used in query include -pan_logs - GP, DHCP logs)

3. Splunk query for - Identifying downloaded files for the endpoint (Datasoucre to be used in query include - pan_logs, Netskope, CB Response file mods)

4. Splunk query for - Identifying email messages received by the affected user from external sources including IOC/attachment information.

5. Splunk query for - Identifying when malware was first seen in the environment. (Looking for first event with malware hash or name - proofpoint, netskope, pan_logs, cbresponse, cbprotect, mcafee )

6. Splunk query for - Identifying 3rd party email use?


Please let me know if you have any questions.



Thanks
Related categories: Software Architecture Splunk