Dashboards & Visualizations

splunk dashboard searching

sam3655
New Member

on the splunk dashboard, is there a way to search for origin/source of a malware attack?

Tags (1)
0 Karma

sam3655
New Member

FireEye monitors our network and catches Malware Callbacks, I'm looking for a script tell me who sent the Malware?

0 Karma

lloydknight
Builder

Not very familiar with FireEye logs but logs can be pretty straightforward at most times. If source and destination IPs are visible in the logs, and you know what specific Malware attack to look up to then it's just a matter of identifying what time it occurred.

And if the source is not available in the logs, you'll just have to index the logs that contain the source (most likely firewall and network logs) then try to correlate it with the logs that contain the Malware attack.

Regarding the script that you're asking, you mean search query?

0 Karma

DalJeanis
Legend

Yes. NO. Maybe. It depends.

It depends on what you mean by "dashboard". It depends on what kind of attack. It depends on what your organization actually puts in splunk.

So, please update your question to be VERY specific.

We experienced an ABC attack, which
had THIS effect on our
organization/network/data.

What log data would we need to have
captured in order to determine the
source of the attack? What resources
are available in the splunk platform
to help us track that down?

0 Karma

lloydknight
Builder

your question is vague.

Assuming you're indexing logs containing the Malware attack and given that you know what type of attacks were executed on a certain time, yes, you can search that malware attack.

0 Karma

sam3655
New Member

is there a script for the search?

0 Karma

akocak
Contributor

are you looking at table or raw event data?
Moreover, origin in the sense of ip look lookup? Can you share more about what do you see?

thanks

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...