Security

How to achieve IP scanners scanning many IPs on a single port usecase?

AL3Z
Builder

Hi,
I'm trying to work on the IP scanners scanning many IPs on a single port usecase on splunk 
index=firewall sourcetype="firewall_cloud" dest_port="   "
| stats count by src_ip,dest_port
| where count >3

I'm not sure which dest_port we need to use over here or we need to take the src_port  if needed pls edit the search 
thanks..

Labels (4)
Tags (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @AL3Z,

Please try below, it will show you any scanner host that scans many destination IP addresses for only one port.

index=firewall sourcetype="firewall_cloud" dest_port="*"
| stats dc(dest_ip) as dest_count by src_ip dest_port
| where dest_count >3
If this reply helps you an upvote and "Accept as Solution" is appreciated.
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...