How to achieve IP scanners scanning many IPs on a single port usecase?


I'm trying to work on the IP scanners scanning many IPs on a single port usecase on splunk 
index=firewall sourcetype="firewall_cloud" dest_port="   "
| stats count by src_ip,dest_port
| where count >3

I'm not sure which dest_port we need to use over here or we need to take the src_port  if needed pls edit the search 

Labels (4)
Tags (1)
0 Karma


Hi @AL3Z,

Please try below, it will show you any scanner host that scans many destination IP addresses for only one port.

index=firewall sourcetype="firewall_cloud" dest_port="*"
| stats dc(dest_ip) as dest_count by src_ip dest_port
| where dest_count >3
If this reply helps you an upvote is appreciated.
Get Updates on the Splunk Community!

There's No Place Like Chrome and the Splunk Platform

Watch On DemandMalware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

The Great Resilience Quest: 5th Leaderboard Update

The fifth leaderboard update for The Great Resilience Quest is out >> 🏆 Check out the ...

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...