* Messages
* Settings
* Activity
* Help
* Find
C:\Program Files\Splunk\etc\apps\user-prefs\default\user-prefs.conf
/opt/splunk/etc/apps/user-pref/default/user-prefs.conf
Tabs
Settings > Data > Data Inputs
contains further sources
Add Data
| metadata type=sourcetypes index=botsv2 | eval firstTime=strftime(firstTime,"%Y-%m-%d %H:%M:%S") | eval lastTime=strftime(lastTime,"%Y-%m-%d %H:%M:%S") | eval recentTime=strftime(recentTime,"%Y-%m-%d %H:%M:%S") | sort - totalCount
sh
index="botsv2" 10.0.2.101 sourcetype="stream:HTTP" | dedup site | table site
sigma: APT29
as inputsource="<source>" | top limit=5 EventID
Social_engineering