Skip to content

Splunk Server

P4T12ICK edited this page Feb 20, 2020 · 2 revisions

Access

The Web UI of the Splunk Server can be accessed over Port 8000.

Apps

The Splunk Server comes with the following Apps pre-installed and configured:

Indexes

The data are stored in the following indexes:

  • index=win : Windows Event Logs, Sysmon Logs, PowerShell Logs
  • index=attack : Log Events from the Attack Simulation with Atomic Red Team and Caldera