Пікірлер
@prashantnagrare8229
@prashantnagrare8229 4 сағат бұрын
Hi, Can we get the link for the indexes.conf file shown in the video and steps to upload it in splunk ? I am not able to find it. Could you please help ?
@lamecreations_guides
@lamecreations_guides 2 сағат бұрын
Hit me up on discord and I'll get you the indexes.conf file.
@salvopala81
@salvopala81 17 сағат бұрын
number 1 !!! you saved my day 🙂
@lamecreations_guides
@lamecreations_guides 13 сағат бұрын
Glad it worked
@primaryJeemail
@primaryJeemail Күн бұрын
Felt hard to understand as we dived immediately into chart. I was under impression we start with basic searches and navigate to this. can you mention the syntax of the command for reference?
@lamecreations_guides
@lamecreations_guides 17 сағат бұрын
hit me up on discord and I can walk you through it.
@primaryJeemail
@primaryJeemail 3 күн бұрын
Option D. We can go to edit dashboard and can move the panel to different location in dashboard. Correct?
@lamecreations_guides
@lamecreations_guides 3 күн бұрын
Got to love test banks. I don't disagree with your response, but with all exams, you answer how they want you to answer, not the way that life really works. CISSP is notorious for this exact same thing.
@blackxmods
@blackxmods 6 күн бұрын
This is super helpful! I like how you used the makeresults as quick work around to not having the data needed for demonstration purposes. I was wondering if you can potentially make a video on creating small scale purple lab environment with sysmon on the victim box. I’m not sure what experience you have with red team operations but even performing some TTP’s in MITRE against that box and then going in splunk and hunting for that data.
@lamecreations_guides
@lamecreations_guides 5 күн бұрын
I keep missing my self imposed deadlines, but your suggestion is exactly where I'm going with this channel. Purple teaming is where I'm ultimately trying to go to, those videos should be coming in the next few months. (I meant to start releasing them january 2025, but they aren't ready yet)
@prashantnagrare8229
@prashantnagrare8229 6 күн бұрын
Thanks for your Videos. I got stuck at 04:13 in SOAR user role creation step. It is showing "ERROR: At least one of the following roles is required to view this page: splunk_app_soar, splunk_app_soar_dashboards, or admin. Contact your Splunk administrator for access." Its looks , we cannot create roles in Splunk Free version and hence we cannot proceed ahead. This all started with below error snapshot: "Fetch roles collection failed. Details: [object Response]"
@jeffmstella
@jeffmstella 7 күн бұрын
Thank you for this!
@lamecreations_guides
@lamecreations_guides 7 күн бұрын
You're welcome, glad it helped!
@l30sosa
@l30sosa 8 күн бұрын
Nice video! I’ve run the Splunk Secure Gateway and added devices. However, now my dashboards either won’t run on the mobile devices or the app crashes while loading. How would you recommend I troubleshoot this issue?
@lamecreations_guides
@lamecreations_guides 8 күн бұрын
Interesting. Is it all dashboards, or specific dashboards that cause the crash? Have to tried it on multiple devices? Just looking to try to find a root cause
@amitsaxena0709
@amitsaxena0709 10 күн бұрын
Is this available via member only videos too in the channel?
@lamecreations_guides
@lamecreations_guides 9 күн бұрын
Yes it is available to lame Braintrust members as well in my members only playlists.
@NoMoneyHeadsUp
@NoMoneyHeadsUp 11 күн бұрын
Nice! Unfortunately some environments do not like saving logs on a splunk server for whatever reason, so they force you to go source > syslog > splunk
@infinit3i
@infinit3i 14 күн бұрын
i needed this, thank you.
@lamecreations_guides
@lamecreations_guides 14 күн бұрын
Glad it helped!
@blackxmods
@blackxmods 14 күн бұрын
Becoming a member of your channel is hands down the best decision I've made in my journey as cybersecurity analyst. I've been privileged to go to some very expensive training on various tools and you blow them out of the water with your teaching skills. Definitely a gifted talent you have! Congrats to those who won!!!
@taynara512
@taynara512 14 күн бұрын
HI LAme after aply yhe command my interface vmbr0 stop working , there is way to convert or remove the command ?
@lamecreations_guides
@lamecreations_guides 14 күн бұрын
not sure, I can ask around and see if anyone know what to do to undo those changes.
@salvopala81
@salvopala81 17 сағат бұрын
from chat GPT sudo brctl setageing vmbr0 300 sudo brctl setfd vmbr0 15
@nischalreddy27
@nischalreddy27 15 күн бұрын
Thank you Team.
@nischalreddy27
@nischalreddy27 15 күн бұрын
Congratulations Circa 🎉
@nischalreddy27
@nischalreddy27 15 күн бұрын
Congratulations Jeff 🎉
@nischalreddy27
@nischalreddy27 15 күн бұрын
Congratulations vishnu 🎉
@RubenMuñozAragon-e9n
@RubenMuñozAragon-e9n 16 күн бұрын
Thanks for the content. How can I tru to be a expert solunker if habe only 60 days free trial of Splunk? Thanks
@lamecreations_guides
@lamecreations_guides 16 күн бұрын
uninstall and reinstall - you'll have 60 days again. Use scripts to automate this and it becomes even easier. Use cribl and reduce down your log ingest to under 500 mb (which is actually really easy to do and I am not saying to stop ingesting logs, just don't get charged for that ingestion) All of these methods will help you get well on your way to being a splunk ninja. Hit me up on discord if you have any questions.
@RubenMuñozAragon-e9n
@RubenMuñozAragon-e9n 16 күн бұрын
Gracias
@lamecreations_guides
@lamecreations_guides 16 күн бұрын
de nada
@danishuddin9752
@danishuddin9752 17 күн бұрын
Absolutely amazing!
@lamecreations_guides
@lamecreations_guides 17 күн бұрын
Glad you liked it
@infinit3i
@infinit3i 18 күн бұрын
love it
@lamecreations_guides
@lamecreations_guides 18 күн бұрын
Glad you liked it.
@drewpetricc
@drewpetricc 20 күн бұрын
Totally helped, thanks!
@lamecreations_guides
@lamecreations_guides 20 күн бұрын
Glad it helped
@abdiwahidahmed6826
@abdiwahidahmed6826 23 күн бұрын
Lame creation, please 🙏 can you develop a splunk cloud course in splunk cloud free trail as a course as soc lab I have challenge on how to setup
@lamecreations_guides
@lamecreations_guides 22 күн бұрын
Come chat with me on discord and help me understand what are the struggles, and I'll see what I can do.
@abdiwahidahmed6826
@abdiwahidahmed6826 21 күн бұрын
@lamecreations_guides which channel do I chat with
@lamecreations_guides
@lamecreations_guides 20 күн бұрын
On my discord, just the the general chat is good, or on suggestions, or hit me up on a dm
@Poovendran-c2s
@Poovendran-c2s 24 күн бұрын
Nice explanation. Unfortunately rename is not working for me.
@lamecreations_guides
@lamecreations_guides 24 күн бұрын
Hit me up on discord and we can have a quick chat. I'm more than willing to see if I can help
@PaulJeffery81
@PaulJeffery81 Ай бұрын
Awesome tutorial!! I've been doing search bootcamps/workshops for Splunk users and the first thing I teach them is how to use the fields command. Everyone starts off with Verbose searches to see all the fields and check their respective values for which ones they want to use. Fields command is great to use for this because it teaches the importance of not only finding the fields they NEED, but also savings a lot of time waiting for the searches to return. Lastly, when saving reports for later or for dashboards, it never hurts to keep the fields command there. Yes, reports in a dashboard basically run as "fast" searches, but it is good practice to use fields whenever one can.
@lamecreations_guides
@lamecreations_guides Ай бұрын
I agree with everything you said.
@MattCale
@MattCale Ай бұрын
very useful for a beginner -- thank you for adding high quality instructions on a complex piece of software 🙇‍♂
@lamecreations_guides
@lamecreations_guides Ай бұрын
Glad it was helpful and thanks for the positive comments.
@ShakeerAkramashu
@ShakeerAkramashu Ай бұрын
Good job..
@lamecreations_guides
@lamecreations_guides Ай бұрын
Glad you liked it!
@michaelventarola7100
@michaelventarola7100 Ай бұрын
I don't see any links or these courses
@lamecreations_guides
@lamecreations_guides Ай бұрын
That's embarrassing. They've been added now. Thank you for letting me know.
@irocz5150
@irocz5150 Ай бұрын
Just order the 2 books...thank you Troy for always help splunk community.
@lamecreations_guides
@lamecreations_guides Ай бұрын
Hope you enjoy them
@irocz5150
@irocz5150 Ай бұрын
Super..checking this now!!!
@lamecreations_guides
@lamecreations_guides Ай бұрын
Glad you are checking it out!
@nischalreddy27
@nischalreddy27 Ай бұрын
Great insights
@nischalreddy27
@nischalreddy27 Ай бұрын
Good one
@lamecreations_guides
@lamecreations_guides Ай бұрын
Thanks, glad you liked it!
@infinit3i
@infinit3i Ай бұрын
I needed this one
@lamecreations_guides
@lamecreations_guides Ай бұрын
Glad it helped
@healthymealthy775
@healthymealthy775 Ай бұрын
Before you update your Splunk version is it needed to update your Splunk apps first?
@lamecreations_guides
@lamecreations_guides Ай бұрын
no, you don't have to typically upgrade your apps before you upgrade your splunk version. The biggest reason you have to upgrade your splunk apps is to support different python lbrary and other programming library changes. But they won't stop you from updating the Splunk System.
@DAFUNKYGINGER
@DAFUNKYGINGER Ай бұрын
If i have a .deb install can i use dpkg and unpack the file into same directory of my current install similar to what you did with the tgz in this video? Basically i guess im asking are all other steps the exact same for a .deb
@lamecreations_guides
@lamecreations_guides Ай бұрын
Make sure to back up your system before doing the upgrade, but yes you should be able to just dpkg the new update and it will act just like the tgz file.
@infinit3i
@infinit3i Ай бұрын
love the content, thank you!
@lamecreations_guides
@lamecreations_guides Ай бұрын
Glad you enjoyed it!