Tips & Tricks Blogs
Latest Articles
template
category
category
Tips & Tricks
hideCategoryPill
true

Eureka! Extracting key-value pairs from JSON fields
Use of Splunk logging driver & HEC (HTTP Event Collector) grows w/ JSON-JavaScript Object Notation; Find answers on extracting key-value pairs from JSON fields.

Spotting the Adversary… with Splunk
Wondering how to find the baddies in huge volumes of data? Work with Splunk & Windows event Log Monitoring – refer to table of event codes in NSA paper.

Configuring Nginx Load Balancer For The HTTP Event Collector
Send data to Splunk w/o a forwarder using HEC (HTTP Event Collector); Perfect for log data over HTTP or IoT. Install Nginx with HTTPS support, then configure.

What size should my Splunk license be?
Learn ways to estimate what size Splunk license you need. How to estimate how much data you have, asking admins, add a buffer, and try a free Splunk trial.

High Performance syslogging for Splunk using syslog-ng – Part 1
Part 1: Implementing syslog with Splunk and three three scenarios you will be able to do so.

High Performance syslogging for Splunk using syslog-ng – Part 2
Part 2: Managing multiple syslogs and what has worked in this Splunkers own experience.

Enriching threat feeds with WHOIS information
Splunk Security continues to grow thanks to insight Splunk Enterprise offers for all data. Finding what’s relevant and how to use the information.

When entropy meets Shannon
Part three on URL analysis, this post will assist you in using Splunk to detect DNS tunnels.

HTTP Event Collector and sending from the browser
Digging deeper into the HTTP Event Collector issue and workarounds for Splunk that could lead to a better, more efficient solution.