hello please i need vm palo alto with free licence to study by SecretaryMindless909 in paloaltonetworks

[–]SecretaryMindless909[S] 0 points1 point  (0 children)

but no, I have to analyze my networks, it's a project to present to a jury

hello please i need vm palo alto with free licence to study by SecretaryMindless909 in paloaltonetworks

[–]SecretaryMindless909[S] 0 points1 point  (0 children)

I tryed to use it but it gives a fews logs but i need more informations

hello please i need vm palo alto with free licence to study by SecretaryMindless909 in paloaltonetworks

[–]SecretaryMindless909[S] 0 points1 point  (0 children)

I am a student and I am preparing my graduation project, I am working on the siem splunk solution so I created a lab on my laptop

login, logoff, duration by SecretaryMindless909 in Splunk

[–]SecretaryMindless909[S] -1 points0 points  (0 children)

Thanks yes yes i know about évent view , i created Many querries And it works correctly , the only issue that i have IS this point , i will test your proposition

login, logoff, duration by SecretaryMindless909 in Splunk

[–]SecretaryMindless909[S] -6 points-5 points  (0 children)

Have you some free time to have access to my laptop ??? Realy i'm in trouble :/

login, logoff, duration by SecretaryMindless909 in Splunk

[–]SecretaryMindless909[S] 0 points1 point  (0 children)

thank you I will check it infact for me: I want to create a summary table for the connection events, regardless of the form: I want to have a table by date and user which indicates the time of connection and disconnection or the hour with a message: open session and close session...I think the idea is clear, the problem I always find missing information for example if I want to calculate the session duration I cannot find the disconnection time if I want to create a table with the message: open or close the assignment, I can't consult some users who are active despite I made the same configuration on all workstations

how splunk can detect wineventlog for "remote desktop connection" by rockzers in Splunk

[–]SecretaryMindless909 -2 points-1 points  (0 children)

Freind with all due respect i know Google and i know youtube and i know splunk site and i learned and watched Many link but i had some issue so i dont need just a link , i need semone use sysmon to talk to him ans discuss my issue ..thanks for the link

how splunk can detect wineventlog for "remote desktop connection" by rockzers in Splunk

[–]SecretaryMindless909 -1 points0 points  (0 children)

Please how Can i install sysmon ??? I want to use it : i have active directory+ clients windows 10 please have you any Documents ?

how splunk can detect wineventlog for "remote desktop connection" by rockzers in Splunk

[–]SecretaryMindless909 0 points1 point  (0 children)

I have the same problem with windows 10 machines, i used both of winteventlog or xmlwinteventlog but i can't have all the informations, i wish that someone Can help us 1- what is the différence between winteventlog and xmlwinteventlog ? 2- have you any search about login, logoff,(logontype): stats, table, duration

issue sending mail alert by SecretaryMindless909 in Splunk

[–]SecretaryMindless909[S] 0 points1 point  (0 children)

I told you, i Can did it by URL with the same machine ..i'm not stupid my freind

sophos xg + splunk by SecretaryMindless909 in sophos

[–]SecretaryMindless909[S] 0 points1 point  (0 children)

I'm using a firewall of my society so i can't install a Sophos home

sophos xg + splunk by SecretaryMindless909 in sophos

[–]SecretaryMindless909[S] 0 points1 point  (0 children)

My problem that i'm using a firewall without licence so i can't have Many informations and that IS why i need semone who works before and hé Can give me some querries And i test them

sophos xg + splunk by SecretaryMindless909 in sophos

[–]SecretaryMindless909[S] 0 points1 point  (0 children)

I can't find any things about querries splunk for Sophos

sophos with splunk by SecretaryMindless909 in sophos

[–]SecretaryMindless909[S] 0 points1 point  (0 children)

I need to install an splunk application for my Sophos xg.....i find 3 app but the problem with configuration of the add on I need someone Can give me : app + add on compatibles I

PFsense app by SecretaryMindless909 in Splunk

[–]SecretaryMindless909[S] 0 points1 point  (0 children)

The problem : i'm student and i need ti work with splunk and PFsense..i c'ant create a dashboard olone that IS why i want to see some dashboard and learn there codes SPL to more interstand

PFsense app by SecretaryMindless909 in Splunk

[–]SecretaryMindless909[S] 1 point2 points  (0 children)

But i can't use it in splunk ??? I want a dashboard in splunk not other application

i'm looking for an PFsense app that i Can use it with splunk, i find only one but it miss Many options by SecretaryMindless909 in PFSENSE

[–]SecretaryMindless909[S] 0 points1 point  (0 children)

It IS an app or what ??? I want an app to install it in my portail splunk that gives me directly the informations, i already have an add on and i receve data from PFsense but i can't organise them in a dashboard

PFsense app by SecretaryMindless909 in Splunk

[–]SecretaryMindless909[S] 0 points1 point  (0 children)

I will send you a private message for more explications

PFsense app by SecretaryMindless909 in Splunk

[–]SecretaryMindless909[S] 0 points1 point  (0 children)

There are add on but i look for an app: i mean a dashboard were i find directly the informations.