Security

Scanning

InqPrice
New Member

Hello Splunk Community!

I am brand new to Splunk and all it's glory and I've been tasked to try and show what is currently scanning our environment and any basic information that goes with that. We have all of our firewall logs flowing into Splunk currently. I've been researching some search queries online but I wanted to ask the community for your input and see what helpful add-ons or tips you can provide me in this task. Anything for internal, external scanning and potentially setting up an alert when a new host has reached a specific threshold for excessive scanning.  Thank you for your time!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @InqPrice,

at first welcome it's a pleasure to have you between us!

About your needs let me understand: your problem is to identify what to search in your logs or how to search in your logs?

if your need is what to search, the best approach is to search in the firewalls documentation error or special conditions to search in Splunk, remember that to do a job in Splunk: 70% is the knowledge of the technology to monitor and 30% is the Splunk knowledge.

I don't know which firewall technologies you have, probably someone of them already have specific apps and you can start from them in your analysis, so try to search in splunkbase (apps.splunk.com) and define with your firewall specialists the Use Cases to implement.

Another ides is to use Google to search questions in our Community about your technologies.

If you need is instead how to search in your logs, Splunk share training and tutorials (some for free and some for a fee), these are some initial free examples:

https://docs.splunk.com/Documentation/Splunk/8.2.0/SearchTutorial/WelcometotheSearchTutorial

https://www.splunk.com/en_us/training/free-courses/splunk-fundamentals-1.html

and many videos on YouTube.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...