Splunk Talks
Splunk Talks
  • Видео 14
  • Просмотров 96 699
Detect AWS S3 Public Buckets using Splunk
video demonstrates how to detect AWS S3 buckets which can be accessed by anyone on the internet.
0:12 prerequisites
0:20 AWS policy
1:59 Sample s3 bucket policies
2:45 detection logic
4:04 why to detect s3 buckets that are exposed to public
5:32 demo
Просмотров: 1 013

Видео

splunk search fundamentals
Просмотров 7262 года назад
explains how splunk search pipeline works
Splunk - Alert Action - Upload Search Results to AWS S3
Просмотров 1,2 тыс.2 года назад
demonstrates how to use use Alert action - Upload Search Results to AWS S3 splunkbase.splunk.com/app/5273/
Splunk Enterprise installation on MacBook M1 Chip/Processor
Просмотров 4 тыс.2 года назад
video demonstrate different ways of installation of Splunk Enterprise on MacBook Air or Pro with M1 Chip. Splunk Enterprise instllation splunk.com Splunk Enterprise installation on MacOS docs.splunk.com/Documentation/Splunk/latest/Installation/InstallonMacOS In case if you founnd the error "zsh: bad CPU type in executable: /opt/splunk/bin/splunk" while starting the Splunk serivce then run below...
splunk if else with more examples
Просмотров 1,9 тыс.3 года назад
video is about how to use if function in different scenarios with more examples. video explains 4 different examples with different functions. 0:14 How to use match function in if with eval command|match function with regex 5:31 How to use Boolean expressions AND and OR in if function with eval command 7:57 How to use informational functions such as isnotnull and isnull in if function with eval...
Splunk eval if else
Просмотров 7 тыс.3 года назад
Video is about how to use if else conditional statement in Splunk eval command.
Splunk & ServiceNow Integration Best Practices 2020
Просмотров 3,1 тыс.4 года назад
1. Best practices in setting up service now add-on 2. How to avoid common mistakes while creating new index. Splunk index configuration calculator - splunk-index.uc.r.appspot.com/
Splunk UseCase | Splunk Alert | Splunk Detect Brute force
Просмотров 11 тыс.4 года назад
Splunk UseCase | Splunk Alert | Splunk Detect Brute force Explains how to detect successful brute force. unlike counting excessive number of failed logins and at least one successful login. This detects successful authentication after n number of consecutive failed logins. sample events used in video : github.com/splunkps/others/blob/4ca103e272e9b1896c380dbd545f167be5ed8ced/brute-force-sample.csv
Splunk Commands | Splunk stats | Splunk eventstats
Просмотров 14 тыс.4 года назад
This video is all about functions of stats & eventstats. explained most commonly used functions with real time examples to make everyone understand easily. splunk stats doc : docs.splunk.com/Documentation/Splunk/8.0.5/SearchReference/Stats splunk eventstats doc : docs.splunk.com/Documentation/Splunk/8.0.5/SearchReference/Eventstats splunk transforming commands doc : docs.splunk.com/Splexicon:Tr...
Splunk Components | universal forwarder | Heavy forwarder
Просмотров 6 тыс.4 года назад
Describes : Splunk software packages 0:06 Splunk Universal forwarder 0:30 Splunk Event Parsing 1:42 all different Splunk Enterprise components Heavy forwarder 2:34 Indexer 3:41 Search head 4:45 Cluster Master 5:24 Deployer 6:41 Deployment Server 6:59 License Master 8:09
Splunk Fields | Knowledge objects | Splunk Field aliases | Splunk Calculated Fields
Просмотров 5 тыс.4 года назад
Splunk Fields | Knowledge objects | Splunk Field aliases | Splunk Calculated Fields Field aliases properties 5:16 Why to create field aliases 5:53 How to create and use field aliases 6:44 How to create field alias using Splunk web 7:22 How to create field alias using CLI 9:34 How to manage field aliases 11:17 Why to create Calculated fields 13:18 How to create calculated fields using Splunk web...
Splunk knowledge objects | Splunk Lookups | Splunk Lookups Part 1
Просмотров 6 тыс.4 года назад
Splunk knowledge objects | Splunk Lookups | Splunk Lookups Part 1 This video is about splunk csv and kv-store lookups. Pros & Cons of CSV lookups Pros & Cons of KVStore Lookups
Splunk knowledge objects | Splunk Lookups | Splunk Lookups Part 2
Просмотров 4,4 тыс.4 года назад
Splunk knowledge objects | Splunk Lookups | Splunk Lookups Part 2 This video is about : How to create CSV lookups 0:40 How to view Lookup data in search 3:49 How to do lookups for event data 5:03 How to Define CSV lookups 7:53 How to do case sensitive & case insensitive lookups in search 9:22 How to do wildcard match 11:04 How to do CIDR match 14:26 How to define Kvstore lookups 16:22 How to mi...
Regular Expressions in Splunk | Splunk Fields | Splunk Field Extractions
Просмотров 31 тыс.4 года назад
Regular Expressions in Splunk | Splunk Fields | Splunk Field Extractions video shows how to extract fields using regular expressions in Splunk Have used regex101.com to demonstrate regular expressions.

Комментарии

  • @danteeep
    @danteeep 16 дней назад

    nice

  • @JawagalSrinathN
    @JawagalSrinathN Месяц назад

    If it show "zsh: bad CPU type in executable: /Applications/splunk/bin/splunk" then try to install "rosetta" -> this helps Intel Apps works with arm based systems like M1,2,3,4 (developed by Apple) command to install : "softwareupdate --install-rosetta" if in case want to remove rosetta after usage : command to uninstall : "sudo /usr/sbin/softwareupdate --remove-rosetta"

  • @AswinMac-nf6ev
    @AswinMac-nf6ev Месяц назад

    In terminal it shows failed to open can you clarify it

  • @rangav8638
    @rangav8638 2 месяца назад

    Thanks for posting this. Searching for this exact one.

  • @MrGuyFaux
    @MrGuyFaux 4 месяца назад

    Fantastic tutorial! Thank you!

  • @SplunkTalks
    @SplunkTalks 4 месяца назад

    In case if you founnd the error "zsh: bad CPU type in executable: /opt/splunk/bin/splunk" while starting the Splunk serivce then run below command and once the below command successfully install then you can rerun /opt/splunk/bin/splunk start --accept-license /usr/sbin/softwareupdate --install-rosetta --agree-to-license medium.com/@jithmisha/fix-for-macbook-air-m1-m2-bad-cpu-type-in-executable-error-3719a0a1cb6

  • @prikkles
    @prikkles 6 месяцев назад

    Is the "Splunk Calculated Fields" VS SPL better performance wise ? i.e. | eval plannedStartStrp = strptime(plannedStart, "%Y-%m-%d %H:%M:%S")

  • @ashutoshchauhan8691
    @ashutoshchauhan8691 6 месяцев назад

    Kindly share your contact details

  • @ashutoshchauhan8691
    @ashutoshchauhan8691 6 месяцев назад

    Kindly let us know how we can connect with you

  • @vinodhkumars6149
    @vinodhkumars6149 8 месяцев назад

    please share github link of the codes u hv used,it will be helpful

  • @sadikdudekula1711
    @sadikdudekula1711 9 месяцев назад

    Thanks for detailed explanation

  • @ganeshat1727
    @ganeshat1727 Год назад

    Im looking for complete Splunk class from basic to Administrative could you please share your number so that i can speak over call

  • @harishbabu3206
    @harishbabu3206 Год назад

    Thank you so much for the video

  • @sarithabhise
    @sarithabhise Год назад

    very nicely explained...thank you

  • @ClintEastonz
    @ClintEastonz Год назад

    Do you know if Splunk can be installed using Parallels on Mac M1? I've been considering a Mac Pro and wanted to add Parallels for virtualization so that I can create multiple OS forwarding data, with a separate search head and indexer. How resource intensive is Splunk on the M1?

  • @babua3605
    @babua3605 Год назад

    Best tutorial to start rex learning

  • @HsAero
    @HsAero Год назад

    Looking for a demonstrative explanation for months, this is the best, thanks sir!

  • @odelakumar06
    @odelakumar06 Год назад

    Excellent bro

  • @odelakumar06
    @odelakumar06 Год назад

    Excellent explanation bro

  • @dhakshanamoorthyv153
    @dhakshanamoorthyv153 Год назад

    Hi i have doubt, if one rex command matching two or more xml tags means.Then how to take the second highlighted value?

  • @etombitonga1751
    @etombitonga1751 Год назад

    Great lessons. Can you plz reached out to me, willing to learn more

    • @SplunkTalks
      @SplunkTalks 8 месяцев назад

      t.balaji2k12@gmail.com

  • @vigneshkini9489
    @vigneshkini9489 Год назад

    Great video.. please make more on regex in Kibana too

  • @PiyushDangreIndia
    @PiyushDangreIndia Год назад

    Very helpful. Best tut on the internet.

  • @krishnateja708
    @krishnateja708 Год назад

    Hi Balu, i have a doubt and need help in writing the regular expression.could you please help me?

  • @odelakumar06
    @odelakumar06 Год назад

    Very useful information brother.. in the end you used fields command, however we can also use table command right.. in which scenario we have to use fields command and table command. Please clarify.

  • @rotimiakinbobola2327
    @rotimiakinbobola2327 2 года назад

    Please can I get your email address? or mobile?

  • @ankitsoni5286
    @ankitsoni5286 2 года назад

    how to change color if two fields count not matching

  • @MrAnkitmaster
    @MrAnkitmaster 2 года назад

    Good one 👏🏻 i need to see how we can detect AWS key custodian users who create the KMS keys in splunk? Is cloudtrail contains that data?

  • @chandusubramanyam
    @chandusubramanyam 2 года назад

    Well explained. thanks a lot

  • @londonleath3596
    @londonleath3596 2 года назад

    Great Video

  • @goncalobarbosa7224
    @goncalobarbosa7224 2 года назад

    Thanks for this, it helped me a lot!

  • @hallaliveeru9904
    @hallaliveeru9904 2 года назад

    Please do many other videos on splunk with real time example sir

  • @hallaliveeru9904
    @hallaliveeru9904 2 года назад

    Nice 👍 one

  • @iccanui9053
    @iccanui9053 2 года назад

    good job thank you

  • @arunmdu9769
    @arunmdu9769 2 года назад

    I'm trying to find a solution for matching using regex for last 2 days. Finally your video really helped me. Thank You!!

  • @Dexter_Ops
    @Dexter_Ops 2 года назад

    Very nice contents, thanks

  • @arunjoy352
    @arunjoy352 2 года назад

    Excellent

  • @joyramsarkar9212
    @joyramsarkar9212 2 года назад

    Your code is not running and also u should informed us on file uploading process before start this video..

  • @JayH98
    @JayH98 2 года назад

    Bravo, well done

  • @daryoushjoobbani3125
    @daryoushjoobbani3125 2 года назад

    Hi Sandip, i have a question regarding the chart command. I am trying to execute a search splunk command that shows both the count and percentage of the count in one chart command: so here is an example of splunk command that currently only shows the count and the total count: source="xyz" http_status_code | chart count by path_template, http_status_code | addtotals col=t This command shows each count of the http_status_code (y axis) and the path_template (x axis) and showing the total of the counts of all the http_status_code. Now i need to add the percentage (count/total) of each count when i know the number of counts. e.g. 40 (5%) or something like that. How would i do that using chart? Thanks!

  • @hpanamgipalli
    @hpanamgipalli 2 года назад

    Good video bro

  • @vr5115
    @vr5115 2 года назад

    Best ever video for Regex

  • @logeshshanmugavel4381
    @logeshshanmugavel4381 2 года назад

    Nice explanation

  • @tireless__journey
    @tireless__journey 2 года назад

    Superb video. Very nicely explained along with examples 🙂

  • @ifti9993
    @ifti9993 2 года назад

    Hello, what is the difference tgz and dmg file ?

    • @SplunkTalks
      @SplunkTalks 2 года назад

      apple.stackexchange.com/questions/252421/what-are-the-benefits-of-distributing-applications-via-dmg

  • @samirsapkota7379
    @samirsapkota7379 2 года назад

    Hello can you share the log file

    • @SplunkTalks
      @SplunkTalks 2 года назад

      Hi, I found file. please download the file from github.com/splunkps/others/blob/4ca103e272e9b1896c380dbd545f167be5ed8ced/brute-force-sample.csv

  • @MishoX0123
    @MishoX0123 2 года назад

    Thank you! Very helpful 👌

  • @kssaz3578
    @kssaz3578 2 года назад

    Excellent - coverage & explanation ---- Pls carry on doing these ...!

  • @hiremathhiremath2296
    @hiremathhiremath2296 2 года назад

    I am currently doing on the regex this video is very much help let me know your linkedin profile

    • @SplunkTalks
      @SplunkTalks 2 года назад

      www.linkedin.com/in/balu6645

  • @sowjigottipati6719
    @sowjigottipati6719 2 года назад

    Awesome nd clear explanation about regular expression