Samsam Test File Write


The search looks for a file named "test.txt" written to the windows system directory tree, which is consistent with Samsam propagation.


Samsam Test File Write Help

You must be ingesting data that records the file-system activity from your hosts to populate the Endpoint file-system data-model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data.


Open in Search