Dashboards & Visualizations

splunk dashboard searching

sam3655
New Member

on the splunk dashboard, is there a way to search for origin/source of a malware attack?

Tags (1)
0 Karma

sam3655
New Member

FireEye monitors our network and catches Malware Callbacks, I'm looking for a script tell me who sent the Malware?

0 Karma

lloydknight
Builder

Not very familiar with FireEye logs but logs can be pretty straightforward at most times. If source and destination IPs are visible in the logs, and you know what specific Malware attack to look up to then it's just a matter of identifying what time it occurred.

And if the source is not available in the logs, you'll just have to index the logs that contain the source (most likely firewall and network logs) then try to correlate it with the logs that contain the Malware attack.

Regarding the script that you're asking, you mean search query?

0 Karma

DalJeanis
Legend

Yes. NO. Maybe. It depends.

It depends on what you mean by "dashboard". It depends on what kind of attack. It depends on what your organization actually puts in splunk.

So, please update your question to be VERY specific.

We experienced an ABC attack, which
had THIS effect on our
organization/network/data.

What log data would we need to have
captured in order to determine the
source of the attack? What resources
are available in the splunk platform
to help us track that down?

0 Karma

lloydknight
Builder

your question is vague.

Assuming you're indexing logs containing the Malware attack and given that you know what type of attacks were executed on a certain time, yes, you can search that malware attack.

0 Karma

sam3655
New Member

is there a script for the search?

0 Karma

akocak
Contributor

are you looking at table or raw event data?
Moreover, origin in the sense of ip look lookup? Can you share more about what do you see?

thanks

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...