Cybersecurity Detection Lab: Forwarding Windows Event Logs to Splunk Using Universal Forwarder

แชร์
ฝัง
  • เผยแพร่เมื่อ 25 ต.ค. 2024

ความคิดเห็น • 43

  • @gavinpaultech
    @gavinpaultech ปีที่แล้ว +2

    I finally completed this project! 🥳🥳 This was an amazing project to get hands-on with and troubleshoot. Can't wait to play around more later. Thanks Day!

  • @vivalaheadshot6815
    @vivalaheadshot6815 2 ปีที่แล้ว +3

    Great video! I’ve been looking for someone to go through the process at a steady pace and you have done a excellent job of that. I will definitely be keeping an eye out for newer videos. Keep it up!

  • @ismailbensikali5579
    @ismailbensikali5579 3 หลายเดือนก่อน +1

    Great video

  • @samuelborthwick4867
    @samuelborthwick4867 3 ปีที่แล้ว +4

    Awesome video! I've been trying to figure out how this worked

    • @DayCyberwox
      @DayCyberwox  3 ปีที่แล้ว +1

      Glad to help!

    • @samuelborthwick4867
      @samuelborthwick4867 3 ปีที่แล้ว

      Do you know anything about Threat Intelligence Analysts by any chance in terms of like a home lab?

  • @DHz12
    @DHz12 2 ปีที่แล้ว +1

    Thank you wonderful person!

  • @Lattibo
    @Lattibo 8 หลายเดือนก่อน +3

    Thanks!

    • @DayCyberwox
      @DayCyberwox  8 หลายเดือนก่อน +1

      You're welcome!

  • @RahulVerma-jp8ff
    @RahulVerma-jp8ff ปีที่แล้ว +2

    After doing lab setup how we can see AD logs like creation of user or adding to group in splunk...

    • @DayCyberwox
      @DayCyberwox  ปีที่แล้ว +1

      Generate it by performing those attacks 🙂

  • @mohammadjawadstan9302
    @mohammadjawadstan9302 5 หลายเดือนก่อน

    Hi there, I installed the universal forwarder on windows, installed the microsoft TA too, currently I am able to capture Registry logs but in the logs i receive in splunk indexer, the user who did the action is not in the logs. can you help me pls?

  • @mirzausama233
    @mirzausama233 ปีที่แล้ว +1

    Thanks Man ✌

  • @ildaragishev-yv4iu
    @ildaragishev-yv4iu ปีที่แล้ว +1

    I couldn't connect to the wifi in the Domain Controller. I've done everything you have so far but I have no wifi. Any suggestions?

    • @mustafanoorzaiy4447
      @mustafanoorzaiy4447 11 หลายเดือนก่อน

      Same problem. Did you fix it?

    • @johncambry1093
      @johncambry1093 6 หลายเดือนก่อน

      @@mustafanoorzaiy4447 see the reply

  • @rohitraj2295
    @rohitraj2295 ปีที่แล้ว

    can we use in collect to forward logs to splunk

  • @SecurityNinja
    @SecurityNinja 3 ปีที่แล้ว +2

    nice bro!

  • @Joangelis
    @Joangelis 2 ปีที่แล้ว +2

    How are you connected to the wifi in the Domain Controller? I've done everything you have so far but I have no wifi, so I can't install universal forwarder

    • @charlesbutawan2034
      @charlesbutawan2034 ปีที่แล้ว

      got the same issue. were u able to fix it?

    • @kentrelaustin7196
      @kentrelaustin7196 ปีที่แล้ว

      @@charlesbutawan2034 I had the same issue and I missed the part where I was supposed to change the domain vm network adapter to vmnet3.

    • @charlesbutawan2034
      @charlesbutawan2034 ปีที่แล้ว

      @@kentrelaustin7196 i changed it already but i still get the same issue :/

    • @Qofcyber
      @Qofcyber ปีที่แล้ว

      @@charlesbutawan2034 did you fix it ?

    • @yanfriclips751
      @yanfriclips751 ปีที่แล้ว +10

      I managed to fix it. You have to create a firewall rule on your pfsense interface to allow connections from that machine.
      1. Go to your pfsense web interface from your kali machine as shown in previous videos
      2. After logging in, at the top bar, go to "Firewall" and then "Rules" from the dropdown.
      3. Select the network where your Domain controller is. In my case it was "Organization Network."
      4. Click the "Add" button at the bottom with the arrow pointing downwards.
      5. Change these settings: Action -> Pass, Protocol -> Any, Source -> Any, Destination -> Any.
      6. Click save and finally Apply changes at the top.
      That should give internet access to the machines you want.

  • @enochagyepong9349
    @enochagyepong9349 2 ปีที่แล้ว +2

    Thanks so much for this. Could you share your steps with me

  • @ksaml7oos
    @ksaml7oos ปีที่แล้ว +1

    i didn't find the AD in the splunk forworder

    • @darkarmy7682
      @darkarmy7682 ปีที่แล้ว

      same issue

    • @stephentrozado1121
      @stephentrozado1121 9 หลายเดือนก่อน +1

      Mine just took a while before showing up. Also refreshed the web page.

  • @johncambry1093
    @johncambry1093 6 หลายเดือนก่อน

    HELP, I can't see the "local event logs" option in my splunk interface. From 12:45

    • @akpovonaagbaire6710
      @akpovonaagbaire6710 5 หลายเดือนก่อน +1

      I had the same issue too. I had to copy the inputs.conf file from C:\ProgramFiles\SplunkUniversalForwarder\etc\system\default and paste it at C:\ProgramFiles\SplunkUniversalForwarder\etc\system\local. Hope that helps