Dashboards & Visualizations

splunk dashboard searching

sam3655
New Member

on the splunk dashboard, is there a way to search for origin/source of a malware attack?

Tags (1)
0 Karma

sam3655
New Member

FireEye monitors our network and catches Malware Callbacks, I'm looking for a script tell me who sent the Malware?

0 Karma

lloydknight
Builder

Not very familiar with FireEye logs but logs can be pretty straightforward at most times. If source and destination IPs are visible in the logs, and you know what specific Malware attack to look up to then it's just a matter of identifying what time it occurred.

And if the source is not available in the logs, you'll just have to index the logs that contain the source (most likely firewall and network logs) then try to correlate it with the logs that contain the Malware attack.

Regarding the script that you're asking, you mean search query?

0 Karma

DalJeanis
Legend

Yes. NO. Maybe. It depends.

It depends on what you mean by "dashboard". It depends on what kind of attack. It depends on what your organization actually puts in splunk.

So, please update your question to be VERY specific.

We experienced an ABC attack, which
had THIS effect on our
organization/network/data.

What log data would we need to have
captured in order to determine the
source of the attack? What resources
are available in the splunk platform
to help us track that down?

0 Karma

lloydknight
Builder

your question is vague.

Assuming you're indexing logs containing the Malware attack and given that you know what type of attacks were executed on a certain time, yes, you can search that malware attack.

0 Karma

sam3655
New Member

is there a script for the search?

0 Karma

akocak
Contributor

are you looking at table or raw event data?
Moreover, origin in the sense of ip look lookup? Can you share more about what do you see?

thanks

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Index This | How many sevens are there between 1 and 100?

August 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Enhance Security Operations with Automated Threat Analysis in the Splunk EcosystemAre you leveraging ...

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...