Skip to content

Commit

Permalink
add pano sigs
Browse files Browse the repository at this point in the history
  • Loading branch information
TonyPhipps committed Aug 29, 2024
1 parent a7dcd35 commit abed1e4
Show file tree
Hide file tree
Showing 2 changed files with 4 additions and 1 deletion.
2 changes: 1 addition & 1 deletion Signatures/Splunk/panorama-config-change-spike.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
index=pan_logs sourcetype=pan:config NOT command IN (request, commit) earliest=-1h
| fields index, host, src_user, src, dest, command, path
| bucket _time span=1h
| stats count as change_count values(path) as targets by _time, index, host, src_user, src, dest, command
| stats count as change_count values(path) as targets by index, host, src_user, src, dest, command
| where change_count > 10
3 changes: 3 additions & 0 deletions Signatures/Splunk/panorama-config-change-unknown-user.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
index=pan_logs sourcetype=pan:config NOT command IN (request, commit) NOT src_user IN (user1, user2, user3) earliest=-1h
| fields index, host, src_user, src, dest, command, path
| stats count as change_count values(path) as targets by index, host, src_user, src, dest, command

0 comments on commit abed1e4

Please sign in to comment.