All Apps and Add-ons

In Splunk UBA, ALL domains in anomalies are showing as IP addresses

JK42
Explorer

For some reason all anomalies that use domain names (Suspicious HTTP Redirects, Suspicious Domain Communication, Blacklisted Domain) are only using the IP addresses of my traffic. All of these detections are using Splunk Stream. When I look at the anomalies, it has

"The following features increased the suspiciousness of the requests:

Domain name being an IP"

even though the actual Stream events have the domain names in them. Looking into the stream events it would seem that maybe they are being parsed incorrectly. There is a field listed called "stream.generic.site" which lists the actual domain of the URL and then there is another called "stream.generic.uri_path" that has the rest of the URL. But it looks like UBA is putting the destination IP in the URL when it is correlating the event.

What this means is we cannot whitelist domains because UBA isn't even looking at the domains.

0 Karma
Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...

Security Newsletter Updates | March 2023

 March 2023 | Check out the latest and greatestUnify Your Security Operations with Splunk Mission Control The ...