Security

Query for any suspicious IP address

ephrem3232
Explorer

I'm looking for a splunk query for any suspicious IP address associated with an IP range that was already blocked in the top ten.

Thank you,

Labels (4)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
Questions to help clarify the problem.
What do you consider a "suspicious IP address"?
If the IP range was already blocked then how will an IP address in that range appear in the top ten?
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...