All Apps and Add-ons

How does the Internal Spammers dashboard work in the Splunk App for Microsoft Exchange?

jmccreery
Explorer

There are three settings which can be modified in the dashboard but we haven't been able to find and definitions as to what exactly the parameters are related to and how they interact.

Minimum Messages (defaults to 80)
Message Rate (defaults to 80)
(Time)(defaults to All Time)

Opening the dashboard in a Search reveals this: 'internal-spammer'(80,80)'

1 Solution

jmccreery
Explorer

Finally found what I was looking for - Internal Spammers is a Macro requiring 2 Arguments. Now that I can see the search definition it makes a bit more sense.

View solution in original post

jmccreery
Explorer

Finally found what I was looking for - Internal Spammers is a Macro requiring 2 Arguments. Now that I can see the search definition it makes a bit more sense.

jmccreery
Explorer

Running the internal spammers with parameters (60,60) report for a time period of 60 minutes does this:

Has any account sent to more than 60 people in the previous 60 minutes?
If so, have they sent messages at a rate of more than 60 messages per minute?
If so, send an alert.

0 Karma

ppablo
Retired

Hi @jmccreery

If you could provide more insight on your understanding beyond the definition for folks who might still be in the dark about this, feel free to share 🙂

Patrick

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...