Alerting

Can anyone please help to create a DOS/DDOS alert without using any application in Splunk?

mlm
Explorer

Hello guys,

Can anyone please help me to create a DOS/DDOS alert without using any application in splunk. 

For example: 

if source IPs sending thousands of TCP packets simultaneously within the 15-20 minutes or so.  

I can't seem to find any docs that related to this.

TIA

marioespbaires
Loves-to-Learn

Hello there,

did you find how to do it? if so, may you share it? 😄 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hi
To getting help you must 1st tell what you have on your splunk. Describe your log events, indexes etc.
This is doable if/when you have suitable data in splunk.
r. Ismo
0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...