Good Evening,
The alert Splunk DoS via Malformed S2S Request has been constantly triggering on one specific system, but the universal fowarder on that machine is version 8.2.3.0 and our Splunk ES is version 8.2.5. According to splunk this alert only affects version 7.3.8 and earlier, 8.0.0 - 8.0.8, and 8.1.0 - 8.1.2. Would there be another reason why this alert would trigger on one specific machine? Could certain processes cause this alert to trigger?