<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom IP Reputation in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Custom-IP-Reputation/m-p/482106#M135077</link>
    <description>&lt;P&gt;Schedule a saved search like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|tstats WHERE index=* FROM datamodel=Authentication count(eval(authentication.action=="failure")) AS subtractme count(eval(authentication.action=="success")) AS addme BY host
| inputlookup append=t YourReputationLookup.csv
| stats first(reputation) AS reputation, first(addme) AS addme, first(subtractme) AS subtractme BY host
| eval reputation = reputation + addme - subtractme
| table host reputation
| outputlookup YourReputationLookup.csv
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 12 Nov 2019 01:23:02 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2019-11-12T01:23:02Z</dc:date>
    <item>
      <title>Custom IP Reputation</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Custom-IP-Reputation/m-p/482105#M135076</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;

&lt;P&gt;My end goal is to create a custom IP reputation table that tracks successful and failed logins by IP address and assigns a numeric score as result.  For every successful auth it increments the score by 2 and every fail it decrements the score by 1.  Ideally we would want a ceiling of 20 and a floor of -20.  I realize we would have to play with those thresholds but its a good start. &lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2019 23:21:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Custom-IP-Reputation/m-p/482105#M135076</guid>
      <dc:creator>bbraun</dc:creator>
      <dc:date>2019-11-11T23:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: Custom IP Reputation</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Custom-IP-Reputation/m-p/482106#M135077</link>
      <description>&lt;P&gt;Schedule a saved search like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|tstats WHERE index=* FROM datamodel=Authentication count(eval(authentication.action=="failure")) AS subtractme count(eval(authentication.action=="success")) AS addme BY host
| inputlookup append=t YourReputationLookup.csv
| stats first(reputation) AS reputation, first(addme) AS addme, first(subtractme) AS subtractme BY host
| eval reputation = reputation + addme - subtractme
| table host reputation
| outputlookup YourReputationLookup.csv
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 12 Nov 2019 01:23:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Custom-IP-Reputation/m-p/482106#M135077</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-11-12T01:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: Custom IP Reputation</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Custom-IP-Reputation/m-p/482107#M135078</link>
      <description>&lt;P&gt;hi @bbraun &lt;/P&gt;

&lt;P&gt;try this &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;form hideAppBar="true" hideSplunkBar="true" hideEdit="true" hideTitle="true" hideChrome="true"&amp;gt;
  &amp;lt;label&amp;gt;IP Reputation Checking Dashboard&amp;lt;/label&amp;gt;
  &amp;lt;fieldset submitButton="false"&amp;gt;&amp;lt;/fieldset&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;html id="titlepanel"&amp;gt;
                 &amp;lt;style&amp;gt;.btn-primary { margin: 5px 10px 5px 0; }
                      #reportTitle {
                        float: left;
                        margin-left: 30rem;
                      }
                      img {
                      float:left;
                      }
                      #username {
                        float: right;

                      }
                      #titlepanel{
                      background: #1c2e61;
                      }

                      .dashboard-header {
                          display: none;
                      }

                 &amp;lt;/style&amp;gt;

          &amp;lt;/html&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;Summary || Count of Records- $output$&amp;lt;/title&amp;gt;
      &amp;lt;input type="time" token="timetk" searchWhenChanged="true"&amp;gt;
        &amp;lt;label&amp;gt;Select Time Range&amp;lt;/label&amp;gt;
        &amp;lt;default&amp;gt;
          &amp;lt;earliest&amp;gt;-24h@h&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
        &amp;lt;/default&amp;gt;
      &amp;lt;/input&amp;gt;
      &amp;lt;table&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;finalized&amp;gt;
            &amp;lt;set token="output"&amp;gt;$job.resultCount$&amp;lt;/set&amp;gt;
          &amp;lt;/finalized&amp;gt;
          &amp;lt;query&amp;gt;|makeresults |eval ip="192.0.0.127"&amp;lt;/query&amp;gt;

          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="count"&amp;gt;10&amp;lt;/option&amp;gt;
        &amp;lt;option name="dataOverlayMode"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="drilldown"&amp;gt;cell&amp;lt;/option&amp;gt;
        &amp;lt;option name="percentagesRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
        &amp;lt;option name="rowNumbers"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="totalsRow"&amp;gt;false&amp;lt;/option&amp;gt;
        &amp;lt;option name="wrap"&amp;gt;true&amp;lt;/option&amp;gt;
        &amp;lt;drilldown&amp;gt;
          &amp;lt;set token="ip"&amp;gt;$click.value2$&amp;lt;/set&amp;gt;
        &amp;lt;/drilldown&amp;gt;
      &amp;lt;/table&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
  &amp;lt;row depends="$ip$"&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;input type="checkbox" token="tokReset"&amp;gt;
        &amp;lt;label&amp;gt;&amp;lt;/label&amp;gt;
        &amp;lt;change&amp;gt;
          &amp;lt;unset token="ip"&amp;gt;&amp;lt;/unset&amp;gt;
          &amp;lt;unset token="form.tokReset"&amp;gt;&amp;lt;/unset&amp;gt;
        &amp;lt;/change&amp;gt;
        &amp;lt;choice value="hide"&amp;gt;Close_X&amp;lt;/choice&amp;gt;
        &amp;lt;delimiter&amp;gt; &amp;lt;/delimiter&amp;gt;
      &amp;lt;/input&amp;gt;
      &amp;lt;html&amp;gt;
       &amp;lt;iframe src="https://www.projecthoneypot.org/ip_$ip$" width="100%" height="300"&amp;gt;&amp;gt;&amp;lt;/iframe&amp;gt;
     &amp;lt;/html&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;

&amp;lt;/form&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 12 Nov 2019 09:08:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Custom-IP-Reputation/m-p/482107#M135078</guid>
      <dc:creator>harishalipaka</dc:creator>
      <dc:date>2019-11-12T09:08:46Z</dc:date>
    </item>
  </channel>
</rss>

