Alerting

Why has Splunk DoS via Malformed S2S Request been triggering a system?

aring87
New Member

Good Evening,

The alert Splunk DoS via Malformed S2S Request has been constantly triggering on one specific system, but the universal fowarder on that machine is version 8.2.3.0 and our Splunk ES is version 8.2.5. According to splunk this alert only affects version 7.3.8 and earlier, 8.0.0 - 8.0.8, and 8.1.0 - 8.1.2. Would there be another reason why this alert would trigger on one specific machine? Could certain processes cause this alert to trigger?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...