Author: ryanhorst

FireEye Dashboards Replicated In Splunk

After installing the FireEye app for Spunk and having some issues with it, the app was uninstalled, which left a gap that needed to be filled. So off I went into Splunk land to see if I could scrounge together some decent “dashboard” worthy search queries that could help display important information. Below are a…

Read More »

FireEye Role Based Access Control (RBAC)

Regarding role based access control and Active Directory integration with FireEye back in FEOS versions 7.0.x (webmps), 6.3.2 (emailmps) and 6.4.1 (CMS), we only had the ability to map a single Active Directory group to a single FireEye “role”. And most enterprises would probably have mapped that single group to the Admin role. Well….. Fast…

Read More »