Security

How to achieve IP scanners scanning many IPs on a single port usecase?

AL3Z
Builder

Hi,
I'm trying to work on the IP scanners scanning many IPs on a single port usecase on splunk 
index=firewall sourcetype="firewall_cloud" dest_port="   "
| stats count by src_ip,dest_port
| where count >3

I'm not sure which dest_port we need to use over here or we need to take the src_port  if needed pls edit the search 
thanks..

Labels (4)
Tags (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @AL3Z,

Please try below, it will show you any scanner host that scans many destination IP addresses for only one port.

index=firewall sourcetype="firewall_cloud" dest_port="*"
| stats dc(dest_ip) as dest_count by src_ip dest_port
| where dest_count >3
If this reply helps you an upvote and "Accept as Solution" is appreciated.
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...