Security

How to use IPviking?

masterpiece
Engager

While extracting fields, now I see another option says Perform IPviking for said index. So we can make a correctional for performing same?

0 Karma

Azeemering
Builder

IPviking was part of the splunk "Norse Threat Intel" app. This app is no longer available.

piebob
Splunk Employee
Splunk Employee

you need to provide a LOT more information here--what app are you using? where are you when you see this option?

0 Karma

masterpiece
Engager

I am not using any app, while clicking on Event Action option in any of log its shows perform IPviking for ...

0 Karma

jplumsdaine22
Influencer

IPviking is not a default splunk Event Action so you must be using an app. If you're not sure I would ask your Splunk Administrator. Additionally I am not sure what you mean by: "make a correctional for performing same? "

0 Karma

Azeemering
Builder

IPviking was part of the splunk "Norse Threat Intel" app. This app is no longer available.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...