<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Telecommunication App to ingest RADIUS Account START|STOP record in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Telecommunication-App-to-ingest-RADIUS-Account-START-STOP/m-p/472654#M7276</link>
    <description>&lt;P&gt;For clarity, this question does not pertain to &lt;A href="https://docs.splunk.com/Documentation/SplunkInvestigate/Current/Use/Overview"&gt;Splunk Investigate&lt;/A&gt;.  &lt;/P&gt;</description>
    <pubDate>Thu, 31 Oct 2019 16:38:13 GMT</pubDate>
    <dc:creator>anortrup_splunk</dc:creator>
    <dc:date>2019-10-31T16:38:13Z</dc:date>
    <item>
      <title>Splunk Telecommunication App to ingest RADIUS Account START|STOP record</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Telecommunication-App-to-ingest-RADIUS-Account-START-STOP/m-p/472653#M7275</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;

&lt;P&gt;I have a scenario that we are trying to design for a Telco to improve on overall IP/MSISDN subscriber reputation with Executive Summary or reporting.&lt;/P&gt;

&lt;P&gt;a.  For 2G/3G/4G mobile networks, subscriber ID = MSISDN – using SGSN, GGSN &amp;amp; HLR.&lt;BR /&gt;
i.  An MSISDN is the number associated with a SIM card&lt;BR /&gt;
ii. Usually stored in Calling-Station-Id RADIUS attribute&lt;/P&gt;

&lt;P&gt;b.  For ADSL networks, subscriber ID = ADSL modem login – using the DSLAM &amp;amp; HLR&lt;BR /&gt;
i.  The login ID uniquely identifies the ADSL connection&lt;BR /&gt;
ii. Usually stored in User-Name RADIUS attribute&lt;/P&gt;

&lt;P&gt;We are hoping the SPLUNK Enterprise and Telecommunication App would have capability to retrieve the Calling-Station-Id and the Framed-IP-Address attributes from the START accounting record to update its local (SQL)table - as displayed by the RADIUS capture Attached:&lt;/P&gt;

&lt;P&gt;For 2G/3G/4G/5Gsubscribers, the RADIUS server natively uses the Calling-Station-Id to store the subscriber ID (= the MSISDN number).&lt;/P&gt;

&lt;P&gt;Then an AntiSpam solution can be configured to block the Outbound SPAM emails then share this blocked detection logs with DDEI via Syslog.&lt;/P&gt;

&lt;P&gt;There's expected to be a concise correlation and reporting from the SIEM on the following. Detection by IP - MSISDN - Number of Spam detection - Sender Email ID - Recipient Email ID -  Timestamp of Last event. There should be capability to drill down or further on this as well.&lt;/P&gt;

&lt;P&gt;kindly advise or guide if this splunk App inherently has such capability explained above.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Lionel &lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 11:31:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Telecommunication-App-to-ingest-RADIUS-Account-START-STOP/m-p/472653#M7275</guid>
      <dc:creator>lionel_orishane</dc:creator>
      <dc:date>2019-10-31T11:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Telecommunication App to ingest RADIUS Account START|STOP record</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Telecommunication-App-to-ingest-RADIUS-Account-START-STOP/m-p/472654#M7276</link>
      <description>&lt;P&gt;For clarity, this question does not pertain to &lt;A href="https://docs.splunk.com/Documentation/SplunkInvestigate/Current/Use/Overview"&gt;Splunk Investigate&lt;/A&gt;.  &lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 16:38:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Telecommunication-App-to-ingest-RADIUS-Account-START-STOP/m-p/472654#M7276</guid>
      <dc:creator>anortrup_splunk</dc:creator>
      <dc:date>2019-10-31T16:38:13Z</dc:date>
    </item>
  </channel>
</rss>

