clong / DetectionLab

Automate the creation of a lab environment complete with security tooling and logging best practices
MIT License
4.57k stars 976 forks source link

AWS Terraform Splunk Threat Hunting App not functioning #706

Open sunnyneo opened 2 years ago

sunnyneo commented 2 years ago

Please verify that you are building from an updated Master branch before filing an issue.

Terraform AWS Splunk Threat Hunting

image

Vagrant Splunk Threat Hunting

image

clong commented 2 years ago

@sunnyneo did you generate any threat events?

sunnyneo commented 2 years ago

@clong

I have executed the following command

Screenshot from 2021-09-13 02-10-49

From Terraform AWS Splunk, no alerts or whatsoever image

From Vagrant Splunk, the same command was executed earlier and alerts came up image

clong commented 2 years ago

Thanks for that! Will check it out

sunnyneo commented 2 years ago

@clong

Updates: Just wanna share, I somehow managed to get it working. I am not sure which steps helped but I did

Created file /opt/splunk/etc/apps/ThreatHunting/lookups/threathunting_asset_priority.csv

image

File Content

image

Download and Extracted https://github.com/olafhartong/ThreatHunting/raw/master/files/ThreatHunting.tar.gz

image

And it seems to work now. image

However when I tried some other features like DNS Stacking, it seems to be broken whereas the results never turn up even after waiting for 10 minutes image image image

Some errors found in different search.log image

clong commented 2 years ago

Hi @sunnyneo - I pushed out new AMIs a week or two ago. Any chance you'd be able to check if the threat hunting stuff is still broken?

sunnyneo commented 2 years ago

Hi @clong, thanks for the update.

I have just tried spinning up DetectionLab on US-WEST-1, it seems to work with preliminary testing. I can see some detection triggered on detectionlab.

liviurosioara commented 2 years ago

Hi, I have the same problem as in the original post, this time with ESXi. Any suggestions?