Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

how do I make splunk es to check my uploaded logs #894

Open
maybe-why-not opened this issue Jun 5, 2024 · 1 comment
Open

how do I make splunk es to check my uploaded logs #894

maybe-why-not opened this issue Jun 5, 2024 · 1 comment

Comments

@maybe-why-not
Copy link

I have installed splunk es app and uploaded botsv1.stream_http.json
image
but incident_review and ess_security_posture is not hitting any event
image
how do I make splunk es to check my uploaded logs and generate a list of alerts like below. Please note that I am not checking the logs forwarded by agent, but the log files uploaded on the browser side
image
thank you

@TheLawsOfChaos
Copy link

The BOTS sample data is a single moment in time. So you need to ensure your ES Correlation searches are reviewing events for that time period.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants