Intrusion Detection With Splunk
Introduction
Ingesting Data Sources
index="main" earliest=0Effective Searching Techniques
index="main" | stats count by sourcetypeGeneralized vs. Targeted Queries
index="main" uniwaldo.localindex="main" *uniwaldo.local*index="main" ComputerName="*uniwaldo.local"
Identifying Sysmon Events by EventCode
Advanced Threat Detection and IP Investigation
Targeting Credential Dumping - Sysmon Event Code 10
Creating Effective Alerts
Step-by-Step Alert Query
Last updated