All Apps and Add-ons

In Splunk UBA, ALL domains in anomalies are showing as IP addresses

JK42
Explorer

For some reason all anomalies that use domain names (Suspicious HTTP Redirects, Suspicious Domain Communication, Blacklisted Domain) are only using the IP addresses of my traffic. All of these detections are using Splunk Stream. When I look at the anomalies, it has

"The following features increased the suspiciousness of the requests:

Domain name being an IP"

even though the actual Stream events have the domain names in them. Looking into the stream events it would seem that maybe they are being parsed incorrectly. There is a field listed called "stream.generic.site" which lists the actual domain of the URL and then there is another called "stream.generic.uri_path" that has the rest of the URL. But it looks like UBA is putting the destination IP in the URL when it is correlating the event.

What this means is we cannot whitelist domains because UBA isn't even looking at the domains.

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...