All Apps and Add-ons

Seeking Assistance: Replicating "Predict the Presence of Malware" Model in Splunk's MLTK?

New Member


I am a student conducting research related to the MLTK app of Splunk. One of the topics of my work is to explore and attempt to apply the same model as the "Predict the Presence of Malware" - one of the sample examples in MLTK. I would like to learn more about how the data for this model was collected, such as the firewall used, the operating system, and other relevant details, so that I can reproduce it on my own machine and collect the data as well. As I am new to the security field, any additional information would be greatly appreciated.

Additionally, I have been able to retrieve some of the fields used in the model, such as src_ip, src_port, session_id, serial_number, receive_time, packets_sent, has_known_vulnerability, dst_ip, dest_port, bytes_sent, and bytes_received. However, I am unsure about how to obtain the packets_received field. Any guidance or assistance on retrieving this particular field would be highly valuable.

Thank you.


Labels (1)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...