Tips & Tricks Blogs

Latest Articles

Eureka! Extracting key-value pairs from JSON fields
Tips & Tricks
2 Minute Read

Eureka! Extracting key-value pairs from JSON fields

Use of Splunk logging driver & HEC (HTTP Event Collector) grows w/ JSON-JavaScript Object Notation; Find answers on extracting key-value pairs from JSON fields.
Spotting the Adversary… with Splunk
Tips & Tricks
5 Minute Read

Spotting the Adversary… with Splunk

Wondering how to find the baddies in huge volumes of data? Work with Splunk & Windows event Log Monitoring – refer to table of event codes in NSA paper.
Configuring Nginx Load Balancer For The HTTP Event Collector
Tips & Tricks
3 Minute Read

Configuring Nginx Load Balancer For The HTTP Event Collector

Send data to Splunk w/o a forwarder using HEC (HTTP Event Collector); Perfect for log data over HTTP or IoT. Install Nginx with HTTPS support, then configure.
What size should my Splunk license be?
Tips & Tricks
13 Minute Read

What size should my Splunk license be?

Learn ways to estimate what size Splunk license you need. How to estimate how much data you have, asking admins, add a buffer, and try a free Splunk trial.
High Performance syslogging for Splunk using syslog-ng – Part 1
Tips & Tricks
4 Minute Read

High Performance syslogging for Splunk using syslog-ng – Part 1

Part 1: Implementing syslog with Splunk and three three scenarios you will be able to do so.
High Performance syslogging for Splunk using syslog-ng – Part 2
Tips & Tricks
7 Minute Read

High Performance syslogging for Splunk using syslog-ng – Part 2

Part 2: Managing multiple syslogs and what has worked in this Splunkers own experience.
Enriching threat feeds with WHOIS information
Tips & Tricks
6 Minute Read

Enriching threat feeds with WHOIS information

Splunk Security continues to grow thanks to insight Splunk Enterprise offers for all data. Finding what’s relevant and how to use the information.
When entropy meets Shannon
Tips & Tricks
2 Minute Read

When entropy meets Shannon

Part three on URL analysis, this post will assist you in using Splunk to detect DNS tunnels.
HTTP Event Collector and sending from the browser
Tips & Tricks
2 Minute Read

HTTP Event Collector and sending from the browser

Digging deeper into the HTTP Event Collector issue and workarounds for Splunk that could lead to a better, more efficient solution.