Hello, my little friends.
For example, I made dashboards with most IP who knocking my site and I wanna see ISP.
How me realize it?
This is a great question!
I'd look at this excellent Splunk blog post : https://www.splunk.com/blog/2016/05/02/enriching-threat-feeds-with-whois-information-splunk.html
That should give you almost everything youre asking about, and more! Additionally, you can look on Apps for some of the following apps :
Network Toolkit : https://splunkbase.splunk.com/app/3491/
Domain Tools : https://splunkbase.splunk.com/app/3376/
Whois Addon : https://splunkbase.splunk.com/app/321/
View solution in original post