Hi,
I'm trying to work on the IP scanners scanning many IPs on a single port usecase on splunk
index=firewall sourcetype="firewall_cloud" dest_port=" "
| stats count by src_ip,dest_port
| where count >3
I'm not sure which dest_port we need to use over here or we need to take the src_port if needed pls edit the search
thanks..
Hi @AL3Z,
Please try below, it will show you any scanner host that scans many destination IP addresses for only one port.
index=firewall sourcetype="firewall_cloud" dest_port="*"
| stats dc(dest_ip) as dest_count by src_ip dest_port
| where dest_count >3