DetectionLab icon indicating copy to clipboard operation
DetectionLab copied to clipboard

AWS Terraform Splunk Threat Hunting App not functioning

Open sunnyneo opened this issue 3 years ago • 7 comments

  • Operating System Version:
  • Deploying via (VirtualBox/VMWare/AWS/Azure/ESXi): AWS
  • Vagrant Version (if applicable):

Please verify that you are building from an updated Master branch before filing an issue.

  • Did a git pull before deploying

Description of the issue:

The threat hunting app in splunk either comes with limited events or no event as shown below, not sure if there is any issue with the event logs being captured/forwarded to AWS splunk threat hunting app. I have no issue with my vagrant built.

Terraform AWS Splunk Threat Hunting

image

Vagrant Splunk Threat Hunting

image

sunnyneo avatar Sep 11 '21 10:09 sunnyneo

@sunnyneo did you generate any threat events?

clong avatar Sep 12 '21 17:09 clong

@clong

I have executed the following command

Screenshot from 2021-09-13 02-10-49

From Terraform AWS Splunk, no alerts or whatsoever image

From Vagrant Splunk, the same command was executed earlier and alerts came up image

sunnyneo avatar Sep 12 '21 18:09 sunnyneo

Thanks for that! Will check it out

clong avatar Sep 12 '21 18:09 clong

@clong

Updates: Just wanna share, I somehow managed to get it working. I am not sure which steps helped but I did

Created file /opt/splunk/etc/apps/ThreatHunting/lookups/threathunting_asset_priority.csv

image

File Content

image

Download and Extracted https://github.com/olafhartong/ThreatHunting/raw/master/files/ThreatHunting.tar.gz

image

And it seems to work now. image

However when I tried some other features like DNS Stacking, it seems to be broken whereas the results never turn up even after waiting for 10 minutes image image image

Some errors found in different search.log image

sunnyneo avatar Sep 12 '21 18:09 sunnyneo

Hi @sunnyneo - I pushed out new AMIs a week or two ago. Any chance you'd be able to check if the threat hunting stuff is still broken?

clong avatar Oct 03 '21 22:10 clong

Hi @clong, thanks for the update.

I have just tried spinning up DetectionLab on US-WEST-1, it seems to work with preliminary testing. I can see some detection triggered on detectionlab.

sunnyneo avatar Oct 04 '21 18:10 sunnyneo

Hi, I have the same problem as in the original post, this time with ESXi. Any suggestions?

liviurosioara avatar Oct 08 '21 23:10 liviurosioara