Alerting

How to write a search to alert on anomalous network traffic?

andre_tucker
Path Finder

I would like to be able to take a general baseline of packet count by source IP address (internal) and source port during a particular point in time and alert when a single IP has a single source port whose count is greater than several standard deviations outside the norm. What would be the most efficient way of doing this? I should also note that I will only be looking at ports between 49,000 and 65535.

0 Karma
1 Solution

tjr1775
Path Finder

The easiest and most efficient way to do this is with the Machine Learning Toolkit app. you would select "Detect Numeric Outliers" and then you would write your base search simply as:

sourcetype=xxx (src_port > 49000 AND src_port < 65535), and then select the fields you would like to conduct outlier detection on.

See the screenshot below. You can write normal Splunk alerts from there on the results. That would definitely be the easiest and most efficient. It has all your needed functionality built-in.

alt text

View solution in original post

tjr1775
Path Finder

The easiest and most efficient way to do this is with the Machine Learning Toolkit app. you would select "Detect Numeric Outliers" and then you would write your base search simply as:

sourcetype=xxx (src_port > 49000 AND src_port < 65535), and then select the fields you would like to conduct outlier detection on.

See the screenshot below. You can write normal Splunk alerts from there on the results. That would definitely be the easiest and most efficient. It has all your needed functionality built-in.

alt text

tjr1775
Path Finder

Couple questions- 1) how many unique internal (source) IPs do you have, 2) how long do you want to go back for your historical baseline (30 days? 60 days? 90?), 3) are you dead set on 2x stdev as an outlier detector?, and lastly, 4) do you have the capability to download/install/use the Splunk Machine Learning Toolkit?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

&#x1f342; Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...