clong / clong/DetectionLab

AWS Terraform Splunk Threat Hunting App not functioning

Open
#706 7 comments 0 reactions 0 assignees View on GitHub
Dominant language
HTML
Stars
5k
Forks
1k
PR merge metrics
No merged PRs in 30d

Description

* Operating System Version:
* Deploying via (VirtualBox/VMWare/AWS/Azure/ESXi): AWS
* Vagrant Version (if applicable):

Please verify that you are building from an updated Master branch before filing an issue.
- Did a git pull before deploying
### Description of the issue:
The threat hunting app in splunk either comes with limited events or no event as shown below, not sure if there is any issue with the event logs being captured/forwarded to AWS splunk threat hunting app. I have no issue with my vagrant built.

### Terraform AWS Splunk Threat Hunting
![image](https://user-images.githubusercontent.com/9748813/132944936-e06e80dc-2d49-4ffc-b180-5bd66185e6b2.png)

### Vagrant Splunk Threat Hunting
![image](https://user-images.githubusercontent.com/9748813/132945048-8a419332-0502-4644-8970-d46771bc9b54.png)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.