<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Anthony Reinke &#187; splunk</title>
	<atom:link href="http://www.anthonyreinke.com/tag/splunk/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.anthonyreinke.com</link>
	<description>Just getting a few things out of my head</description>
	<lastBuildDate>Tue, 31 Aug 2010 02:55:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Web (http) Certificate for Splunk</title>
		<link>http://www.anthonyreinke.com/2010/07/09/web-http-certificate-for-splunk/</link>
		<comments>http://www.anthonyreinke.com/2010/07/09/web-http-certificate-for-splunk/#comments</comments>
		<pubDate>Fri, 09 Jul 2010 17:17:13 +0000</pubDate>
		<dc:creator>systm</dc:creator>
				<category><![CDATA[geek]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[ca]]></category>
		<category><![CDATA[cert]]></category>
		<category><![CDATA[certificate]]></category>
		<category><![CDATA[digital]]></category>
		<category><![CDATA[generate]]></category>
		<category><![CDATA[http]]></category>
		<category><![CDATA[self]]></category>
		<category><![CDATA[signed]]></category>
		<category><![CDATA[splunk]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://www.anthonyreinke.com/?p=257</guid>
		<description><![CDATA[I prefer to use a signed web certificate and not the self signed certificate.  I found a couple different topics on the process, but found that most of them referred to the distributive searching certificate.  Here are the step to generate the certificate and get it in to the right place for Splunk to use [...]]]></description>
		<wfw:commentRss>http://www.anthonyreinke.com/2010/07/09/web-http-certificate-for-splunk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Splunk Dashboards</title>
		<link>http://www.anthonyreinke.com/2010/05/02/splunk-dashboards/</link>
		<comments>http://www.anthonyreinke.com/2010/05/02/splunk-dashboards/#comments</comments>
		<pubDate>Mon, 03 May 2010 03:24:38 +0000</pubDate>
		<dc:creator>systm</dc:creator>
				<category><![CDATA[geek]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[work]]></category>
		<category><![CDATA[administration]]></category>
		<category><![CDATA[administrator]]></category>
		<category><![CDATA[app]]></category>
		<category><![CDATA[backup]]></category>
		<category><![CDATA[central]]></category>
		<category><![CDATA[dashboard]]></category>
		<category><![CDATA[log]]></category>
		<category><![CDATA[splunk]]></category>
		<category><![CDATA[system]]></category>

		<guid isPermaLink="false">http://www.anthonyreinke.com/?p=245</guid>
		<description><![CDATA[I have begun building my own dashboards in Splunk.  Once I have the custom views built, I will post them up here.  So far everything I have been working on is with a system's administrator in mind because that is what I have been doing for the past 12 years (wow, thats a long time). [...]]]></description>
		<wfw:commentRss>http://www.anthonyreinke.com/2010/05/02/splunk-dashboards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Another good report</title>
		<link>http://www.anthonyreinke.com/2010/03/24/another-good-report/</link>
		<comments>http://www.anthonyreinke.com/2010/03/24/another-good-report/#comments</comments>
		<pubDate>Wed, 24 Mar 2010 15:54:34 +0000</pubDate>
		<dc:creator>systm</dc:creator>
				<category><![CDATA[geek]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[computer]]></category>
		<category><![CDATA[create]]></category>
		<category><![CDATA[daily]]></category>
		<category><![CDATA[delete]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[id]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[splunk]]></category>
		<category><![CDATA[user]]></category>

		<guid isPermaLink="false">http://www.anthonyreinke.com/?p=239</guid>
		<description><![CDATA[This will help to track down failed logins.  This could be due to someone changing their password and still are logged in to a server with the old account information.  The other side is that someone could be trying to brute force an account. Type="Failure Audit" sourcetype="WinEventLog:Security" &#124; chart count by User_Name &#124; sort - [...]]]></description>
		<wfw:commentRss>http://www.anthonyreinke.com/2010/03/24/another-good-report/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Daily Splunk Reports</title>
		<link>http://www.anthonyreinke.com/2010/03/24/daily-splunk-reports/</link>
		<comments>http://www.anthonyreinke.com/2010/03/24/daily-splunk-reports/#comments</comments>
		<pubDate>Wed, 24 Mar 2010 14:45:14 +0000</pubDate>
		<dc:creator>systm</dc:creator>
				<category><![CDATA[geek]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[computer]]></category>
		<category><![CDATA[create]]></category>
		<category><![CDATA[daily]]></category>
		<category><![CDATA[delete]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[id]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[splunk]]></category>
		<category><![CDATA[user]]></category>

		<guid isPermaLink="false">http://www.anthonyreinke.com/?p=237</guid>
		<description><![CDATA[So I am a full convert and profit of Splunk now.  I have been using it at work for around 4 months now.  I have rolled it out to our domain controllers and have started rolling it to all our Windows and *nix servers.  The ability to find out who did what has made my [...]]]></description>
		<wfw:commentRss>http://www.anthonyreinke.com/2010/03/24/daily-splunk-reports/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Getting more intelligence on how much data splunk is eating.</title>
		<link>http://www.anthonyreinke.com/2010/01/18/getting-more-intelligence-on-how-much-data-splunk-is-eating/</link>
		<comments>http://www.anthonyreinke.com/2010/01/18/getting-more-intelligence-on-how-much-data-splunk-is-eating/#comments</comments>
		<pubDate>Mon, 18 Jan 2010 19:02:57 +0000</pubDate>
		<dc:creator>Anthony</dc:creator>
				<category><![CDATA[geek]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[index]]></category>
		<category><![CDATA[Michael]]></category>
		<category><![CDATA[splunk]]></category>
		<category><![CDATA[Wilde]]></category>

		<guid isPermaLink="false">http://www.anthonyreinke.com/2010/01/18/getting-more-intelligence-on-how-much-data-splunk-is-eating/</guid>
		<description><![CDATA[http://www.splunkninja.com/profiles/blogs/getting-more-intelligence-on Great article from Michael Wilde on how to see how much data you are indexing from Splunk]]></description>
		<wfw:commentRss>http://www.anthonyreinke.com/2010/01/18/getting-more-intelligence-on-how-much-data-splunk-is-eating/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Searching for Account Lockouts with Splunk</title>
		<link>http://www.anthonyreinke.com/2009/12/21/searching-for-account-lockouts-with-splunk/</link>
		<comments>http://www.anthonyreinke.com/2009/12/21/searching-for-account-lockouts-with-splunk/#comments</comments>
		<pubDate>Mon, 21 Dec 2009 22:03:47 +0000</pubDate>
		<dc:creator>Anthony</dc:creator>
				<category><![CDATA[geek]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[account]]></category>
		<category><![CDATA[lockout]]></category>
		<category><![CDATA[search]]></category>
		<category><![CDATA[splunk]]></category>

		<guid isPermaLink="false">http://www.anthonyreinke.com/?p=170</guid>
		<description><![CDATA[This requires that the Splunk agent is getting the security event from the Domain Controller(s). Find the username of the person Log in to the Splunk server. Click on the Search button. Enter the search paramitters to find the user and select your time frame for the search: source="WinEventLog:Security" User_Name="lockedUser" Then check the “Client_Address” field.  [...]]]></description>
		<wfw:commentRss>http://www.anthonyreinke.com/2009/12/21/searching-for-account-lockouts-with-splunk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Monitoring the Filesystem with Splunk</title>
		<link>http://www.anthonyreinke.com/2009/08/31/monitoring-the-filesystem-with-splunk/</link>
		<comments>http://www.anthonyreinke.com/2009/08/31/monitoring-the-filesystem-with-splunk/#comments</comments>
		<pubDate>Mon, 31 Aug 2009 19:17:06 +0000</pubDate>
		<dc:creator>Anthony</dc:creator>
				<category><![CDATA[geek]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[file]]></category>
		<category><![CDATA[filesystem]]></category>
		<category><![CDATA[folder]]></category>
		<category><![CDATA[monitor]]></category>
		<category><![CDATA[server]]></category>
		<category><![CDATA[splunk]]></category>
		<category><![CDATA[system]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.anthonyreinke.com/?p=111</guid>
		<description><![CDATA[I have used OSSEC in the past to watch the file system for changes.  When I found that I can have the Splunk agent handle the monitoring itself, I was pretty excited.  Since I would send my OSSEC data to Splunk anyways, it just seemed logical to have Splunk do everything. In Windows, you need [...]]]></description>
		<wfw:commentRss>http://www.anthonyreinke.com/2009/08/31/monitoring-the-filesystem-with-splunk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RegEx with Splunk for OSSEC</title>
		<link>http://www.anthonyreinke.com/2009/07/30/regex-with-splunk-for-ossec/</link>
		<comments>http://www.anthonyreinke.com/2009/07/30/regex-with-splunk-for-ossec/#comments</comments>
		<pubDate>Fri, 31 Jul 2009 04:12:46 +0000</pubDate>
		<dc:creator>Anthony</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[expression]]></category>
		<category><![CDATA[ossec]]></category>
		<category><![CDATA[regex]]></category>
		<category><![CDATA[regular]]></category>
		<category><![CDATA[splunk]]></category>

		<guid isPermaLink="false">http://www.anthonyreinke.com/?p=75</guid>
		<description><![CDATA[Thanks to Michael Wilde for the information on RegEx in Splunk.  For those like me who aren't the best at RegEx, I will show some of the regular expressions I am using for OSSEC. Server Name (?i) Location:\s\((?P&#60;FIELDNAME&#62;.*?)\)\s Windows Event User (?i) USER: (?P&#60;FIELDNAME&#62;[^:]*); Server IP (?i)^[^\)]*\)\s+(?P&#60;FIELDNAME&#62;[^\-]*)\- Windows Events (?i)^[^\-]*\-\s+(?P&#60;FIELDNAME&#62;[^\.]*)\. LogInUser (?i) Name: (?P&#60;FIELDNAME&#62;\w+) LogInDomain [...]]]></description>
		<wfw:commentRss>http://www.anthonyreinke.com/2009/07/30/regex-with-splunk-for-ossec/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OSSEC and Splunk</title>
		<link>http://www.anthonyreinke.com/2009/07/27/ossec-and-splunk/</link>
		<comments>http://www.anthonyreinke.com/2009/07/27/ossec-and-splunk/#comments</comments>
		<pubDate>Tue, 28 Jul 2009 01:55:54 +0000</pubDate>
		<dc:creator>Anthony</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[hids]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[logs]]></category>
		<category><![CDATA[ossec]]></category>
		<category><![CDATA[splunk]]></category>
		<category><![CDATA[syslog]]></category>
		<category><![CDATA[unix]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.anthonyreinke.com/?p=66</guid>
		<description><![CDATA[I have been playing with OSSEC and Splunk.  OSSEC is a Host based Intrusion Detection System (HIDS).  Splunk is a log archiving and searching system.  OSSEC is open source and is multiple platform.  You can run it on Linux/Unix and Windows.  I am using OSSEC to forward Windows Event Logs to Splunk.  Splunk makes the [...]]]></description>
		<wfw:commentRss>http://www.anthonyreinke.com/2009/07/27/ossec-and-splunk/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
