Monday, November 6, 2023

Project #4 Project Title: DC HA Active Active Duration: 19th Aug 2020 to 18th Dec. 2020

Role - Area:  Splunk Developer – Developer      

Skill Used: Splunk Enterprise, Splunk Enterprise Security 


Description:  

  • Secure Now is a client developed authentication and risk identification service 
  • Anybody who wants an authenticated entry for financial or any other secured transaction can use this 
  • Client wants to monitor IIS Failure and App Tier Failure for Secure Now using Splunk 
  • Dashboard needs to be created to monitor these failures. Alerts should be created to notify any failure 
  • On every triggered alert python script should run which can split the traffic to other server

 

Responsibility:     

  • Use Splunk Enterprise 8.0.6 and monitor the three server errors 
  • Create separate alert and dashboard panel for each error. Analyze IIS Failure Error at the client's Infrastructure.

No comments:

Post a Comment

35 Use Cases using Splunk SIEM to reduce False Positives

Use Case Name 1. BRUTE FORCE ATTACK DETECTION ON WINDOWS SYSTEMS Goal Excludes routine status cod...