Hi, Can we get the link for the indexes.conf file shown in the video and steps to upload it in splunk ? I am not able to find it. Could you please help ?
@lamecreations_guides2 сағат бұрын
Hit me up on discord and I'll get you the indexes.conf file.
@salvopala8117 сағат бұрын
number 1 !!! you saved my day 🙂
@lamecreations_guides13 сағат бұрын
Glad it worked
@primaryJeemailКүн бұрын
Felt hard to understand as we dived immediately into chart. I was under impression we start with basic searches and navigate to this. can you mention the syntax of the command for reference?
@lamecreations_guides17 сағат бұрын
hit me up on discord and I can walk you through it.
@primaryJeemail3 күн бұрын
Option D. We can go to edit dashboard and can move the panel to different location in dashboard. Correct?
@lamecreations_guides3 күн бұрын
Got to love test banks. I don't disagree with your response, but with all exams, you answer how they want you to answer, not the way that life really works. CISSP is notorious for this exact same thing.
@blackxmods6 күн бұрын
This is super helpful! I like how you used the makeresults as quick work around to not having the data needed for demonstration purposes. I was wondering if you can potentially make a video on creating small scale purple lab environment with sysmon on the victim box. I’m not sure what experience you have with red team operations but even performing some TTP’s in MITRE against that box and then going in splunk and hunting for that data.
@lamecreations_guides5 күн бұрын
I keep missing my self imposed deadlines, but your suggestion is exactly where I'm going with this channel. Purple teaming is where I'm ultimately trying to go to, those videos should be coming in the next few months. (I meant to start releasing them january 2025, but they aren't ready yet)
@prashantnagrare82296 күн бұрын
Thanks for your Videos. I got stuck at 04:13 in SOAR user role creation step. It is showing "ERROR: At least one of the following roles is required to view this page: splunk_app_soar, splunk_app_soar_dashboards, or admin. Contact your Splunk administrator for access." Its looks , we cannot create roles in Splunk Free version and hence we cannot proceed ahead. This all started with below error snapshot: "Fetch roles collection failed. Details: [object Response]"
@jeffmstella7 күн бұрын
Thank you for this!
@lamecreations_guides7 күн бұрын
You're welcome, glad it helped!
@l30sosa8 күн бұрын
Nice video! I’ve run the Splunk Secure Gateway and added devices. However, now my dashboards either won’t run on the mobile devices or the app crashes while loading. How would you recommend I troubleshoot this issue?
@lamecreations_guides8 күн бұрын
Interesting. Is it all dashboards, or specific dashboards that cause the crash? Have to tried it on multiple devices? Just looking to try to find a root cause
@amitsaxena070910 күн бұрын
Is this available via member only videos too in the channel?
@lamecreations_guides9 күн бұрын
Yes it is available to lame Braintrust members as well in my members only playlists.
@NoMoneyHeadsUp11 күн бұрын
Nice! Unfortunately some environments do not like saving logs on a splunk server for whatever reason, so they force you to go source > syslog > splunk
@infinit3i14 күн бұрын
i needed this, thank you.
@lamecreations_guides14 күн бұрын
Glad it helped!
@blackxmods14 күн бұрын
Becoming a member of your channel is hands down the best decision I've made in my journey as cybersecurity analyst. I've been privileged to go to some very expensive training on various tools and you blow them out of the water with your teaching skills. Definitely a gifted talent you have! Congrats to those who won!!!
@taynara51214 күн бұрын
HI LAme after aply yhe command my interface vmbr0 stop working , there is way to convert or remove the command ?
@lamecreations_guides14 күн бұрын
not sure, I can ask around and see if anyone know what to do to undo those changes.
Thanks for the content. How can I tru to be a expert solunker if habe only 60 days free trial of Splunk? Thanks
@lamecreations_guides16 күн бұрын
uninstall and reinstall - you'll have 60 days again. Use scripts to automate this and it becomes even easier. Use cribl and reduce down your log ingest to under 500 mb (which is actually really easy to do and I am not saying to stop ingesting logs, just don't get charged for that ingestion) All of these methods will help you get well on your way to being a splunk ninja. Hit me up on discord if you have any questions.
@RubenMuñozAragon-e9n16 күн бұрын
Gracias
@lamecreations_guides16 күн бұрын
de nada
@danishuddin975217 күн бұрын
Absolutely amazing!
@lamecreations_guides17 күн бұрын
Glad you liked it
@infinit3i18 күн бұрын
love it
@lamecreations_guides18 күн бұрын
Glad you liked it.
@drewpetricc20 күн бұрын
Totally helped, thanks!
@lamecreations_guides20 күн бұрын
Glad it helped
@abdiwahidahmed682623 күн бұрын
Lame creation, please 🙏 can you develop a splunk cloud course in splunk cloud free trail as a course as soc lab I have challenge on how to setup
@lamecreations_guides22 күн бұрын
Come chat with me on discord and help me understand what are the struggles, and I'll see what I can do.
@abdiwahidahmed682621 күн бұрын
@lamecreations_guides which channel do I chat with
@lamecreations_guides20 күн бұрын
On my discord, just the the general chat is good, or on suggestions, or hit me up on a dm
@Poovendran-c2s24 күн бұрын
Nice explanation. Unfortunately rename is not working for me.
@lamecreations_guides24 күн бұрын
Hit me up on discord and we can have a quick chat. I'm more than willing to see if I can help
@PaulJeffery81Ай бұрын
Awesome tutorial!! I've been doing search bootcamps/workshops for Splunk users and the first thing I teach them is how to use the fields command. Everyone starts off with Verbose searches to see all the fields and check their respective values for which ones they want to use. Fields command is great to use for this because it teaches the importance of not only finding the fields they NEED, but also savings a lot of time waiting for the searches to return. Lastly, when saving reports for later or for dashboards, it never hurts to keep the fields command there. Yes, reports in a dashboard basically run as "fast" searches, but it is good practice to use fields whenever one can.
@lamecreations_guidesАй бұрын
I agree with everything you said.
@MattCaleАй бұрын
very useful for a beginner -- thank you for adding high quality instructions on a complex piece of software 🙇♂
@lamecreations_guidesАй бұрын
Glad it was helpful and thanks for the positive comments.
@ShakeerAkramashuАй бұрын
Good job..
@lamecreations_guidesАй бұрын
Glad you liked it!
@michaelventarola7100Ай бұрын
I don't see any links or these courses
@lamecreations_guidesАй бұрын
That's embarrassing. They've been added now. Thank you for letting me know.
@irocz5150Ай бұрын
Just order the 2 books...thank you Troy for always help splunk community.
@lamecreations_guidesАй бұрын
Hope you enjoy them
@irocz5150Ай бұрын
Super..checking this now!!!
@lamecreations_guidesАй бұрын
Glad you are checking it out!
@nischalreddy27Ай бұрын
Great insights
@nischalreddy27Ай бұрын
Good one
@lamecreations_guidesАй бұрын
Thanks, glad you liked it!
@infinit3iАй бұрын
I needed this one
@lamecreations_guidesАй бұрын
Glad it helped
@healthymealthy775Ай бұрын
Before you update your Splunk version is it needed to update your Splunk apps first?
@lamecreations_guidesАй бұрын
no, you don't have to typically upgrade your apps before you upgrade your splunk version. The biggest reason you have to upgrade your splunk apps is to support different python lbrary and other programming library changes. But they won't stop you from updating the Splunk System.
@DAFUNKYGINGERАй бұрын
If i have a .deb install can i use dpkg and unpack the file into same directory of my current install similar to what you did with the tgz in this video? Basically i guess im asking are all other steps the exact same for a .deb
@lamecreations_guidesАй бұрын
Make sure to back up your system before doing the upgrade, but yes you should be able to just dpkg the new update and it will act just like the tgz file.