
Can Splunk Alerts check websites?

Path Finder


Is it possible to set up Splunk so that, if a search reports that a website is malicious, it can double check with another website with a blocklist? For example, lets say that the logs Splunk monitor report that a user went to It reports this as a malicious site and sends an alert. Obviously, this would be a false positive, so what I want to know is if it is possible to set up a search query to dynamically check URLs reported against an online blocklist. I realize I could probably set up something like this witha lookup file acting as either a blacklist or a whitelist, but I would like something a bit more dynamic.

1 Solution

Esteemed Legend
0 Karma

Esteemed Legend

Check out the Getwatchlist app:

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

New This Month - Observability Updates Give Extended Visibility and Improve User ...

This month is a collection of special news! From Magic Quadrant updates to AppDynamics integrations to ...

Intro to Splunk Synthetic Monitoring

In our last post, we mentioned that the 3 key pieces of observability – metrics, logs, and traces – provide ...