All Apps and Add-ons

Splunk UBA malware(DGA) Alerts to much

Path Finder

Hi splunkers,
My problem Splunk UBA Malware DGA Alert (Suspicious Domain Name)
in fact this Suspicious Domains are advertising sites
too much dga in an alarm ex: dga count is > 100
AND ı cant control it every sites , indeed one of them can be dga
How can I fix false positives?
alt text
Also that make requests by iphone but alarm can include my dns servers
Sorry for my bad english 🙂
Have a good day :

0 Karma


There are 2 anomalies. It's possible, activities (e.g. browsing) from the phone, visited a number of DGA's and hence Suspicious domain names. What's interesting is the Unusual Geolocation comms. Is it possible, one of the visit to the DGA installed a malware which opens a C2C/backdoor to 197.241.* ip address? You may want to scan your device and check for any unusual apps/programme/external comms.

0 Karma
Get Updates on the Splunk Community!

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...