Reporting

Can I find outside IP addresses hitting our firewall and seeing if they've been blocked or not?

mecksg1
Loves-to-Learn Lots

so im trying to find outside IP addresses hiting our firewall and seeing if they have been blocked or not. is there a script i can run to find them? 

i have this one im trying  index="firewall" src_ip=( IP address here ) and i get nothing

any help will be appreciated

 

Labels (1)
0 Karma

mecksg1
Loves-to-Learn Lots

thanks for the answer, but it did not pull what i need, for some reason its only showing 7 days and nothing for the past 2 days

0 Karma

johnhuang
Motivator

You can run a broader search of that IP address to see where it's being captured and fields it's assigned to.

First try search the ip_address against your firewall index:

  • search index="firewall" <ip_address>

If above doesn't show results, run a global search by specifying only the  ip address 

  • search <ip_address>

 

0 Karma

mecksg1
Loves-to-Learn Lots

ok so i have confirmed that the ports are listening and the firewall is talking to splunk, but splunk is doing nothing with the logs. any ideas?

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...