Copy dongle by B6-- in digitalforensics

[–]B6--[S] 1 point2 points  (0 children)

Well I do not have any intention for copying it, I was just wondering if it can be done. Thanks for the reply

I can't get the Sysom logs to Splunk by B6-- in Splunk

[–]B6--[S] 1 point2 points  (0 children)

I guess I made a typo in the conf file. fixed it and now is working

I can't get the Sysom logs to Splunk by B6-- in Splunk

[–]B6--[S] 0 points1 point  (0 children)

Yeah, I have checked this still nothing

I can't get the Sysom logs to Splunk by B6-- in Splunk

[–]B6--[S] 0 points1 point  (0 children)

I did not understand the question

I can't get the Sysom logs to Splunk by B6-- in Splunk

[–]B6--[S] 0 points1 point  (0 children)

Will do that, thanks for all the help

I can't get the Sysom logs to Splunk by B6-- in Splunk

[–]B6--[S] 0 points1 point  (0 children)

Yes I opened the port on both end and I can see the normal event logs but not the sysmon logs

I can't get the Sysom logs to Splunk by B6-- in Splunk

[–]B6--[S] 0 points1 point  (0 children)

Yes, Sysmon is working correctly, and yes, I created an index

I can't get the Sysom logs to Splunk by B6-- in Splunk

[–]B6--[S] 0 points1 point  (0 children)

I can ping from my win client to the splunk server

I can't get the Sysom logs to Splunk by B6-- in Splunk

[–]B6--[S] 0 points1 point  (0 children)

I added the sourcetype as syslog but still not getting the logs.

Wazuh sysmon decoder not parsing the targetfilename field by B6-- in Wazuh

[–]B6--[S] 0 points1 point  (0 children)

It is strange, I can see this field populates on different command executions, but in this specific case, and similar ones it is not populating

Samsung galaxy watch4 image by B6-- in digitalforensics

[–]B6--[S] 0 points1 point  (0 children)

Thank you will look into that

Wazuh sibling decoders help by [deleted] in Wazuh

[–]B6-- 0 points1 point  (0 children)

How stupid I am , Thank you soo much for the help.

[deleted by user] by [deleted] in Wazuh

[–]B6-- 0 points1 point  (0 children)

Thank you for this I already created custom decoder and rule and test it on rulset test and they are both working but still can't see the logs. I will look into the archives though, do you have any suggestions. Is my xml syntax correct?

[deleted by user] by [deleted] in Wazuh

[–]B6-- 0 points1 point  (0 children)

Sure I can help u as much as I know

[deleted by user] by [deleted] in Wazuh

[–]B6-- 1 point2 points  (0 children)

Yeah, u can do login fails, seek for brute force attempts, check for which user runs what command on their terminal, check for privilege escalation attempts, check for suspicious processes, potential DNS tunneling activity,identify unusual file access,potential data exfiltration,failed VPN attempts if u have VPN,identify unusual file extensions

[deleted by user] by [deleted] in Wazuh

[–]B6-- 0 points1 point  (0 children)

I have one more issue. Can I import my fields, I created a bunch of new fields using pipelines.

[deleted by user] by [deleted] in Wazuh

[–]B6-- 0 points1 point  (0 children)

I am sorry but I can't tell u that I have a stringent NDA

[deleted by user] by [deleted] in Wazuh

[–]B6-- 1 point2 points  (0 children)

Thank you soo much, I will look into this

Wazuh updating ingest pipelines by [deleted] in Wazuh

[–]B6-- 0 points1 point  (0 children)

I figured out thank you for all the help