Alerting

Can anyone please help to create a DOS/DDOS alert without using any application in Splunk?

mlm
Explorer

Hello guys,

Can anyone please help me to create a DOS/DDOS alert without using any application in splunk. 

For example: 

if source IPs sending thousands of TCP packets simultaneously within the 15-20 minutes or so.  

I can't seem to find any docs that related to this.

TIA

marioespbaires
Loves-to-Learn

Hello there,

did you find how to do it? if so, may you share it? 😄 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hi
To getting help you must 1st tell what you have on your splunk. Describe your log events, indexes etc.
This is doable if/when you have suitable data in splunk.
r. Ismo
0 Karma
Get Updates on the Splunk Community!

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Splunk Education Goes to Washington | Splunk GovSummit 2024

If you’re in the Washington, D.C. area, this is your opportunity to take your career and Splunk skills to the ...