Security

Scanning

InqPrice
New Member

Hello Splunk Community!

I am brand new to Splunk and all it's glory and I've been tasked to try and show what is currently scanning our environment and any basic information that goes with that. We have all of our firewall logs flowing into Splunk currently. I've been researching some search queries online but I wanted to ask the community for your input and see what helpful add-ons or tips you can provide me in this task. Anything for internal, external scanning and potentially setting up an alert when a new host has reached a specific threshold for excessive scanning.  Thank you for your time!

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @InqPrice,

at first welcome it's a pleasure to have you between us!

About your needs let me understand: your problem is to identify what to search in your logs or how to search in your logs?

if your need is what to search, the best approach is to search in the firewalls documentation error or special conditions to search in Splunk, remember that to do a job in Splunk: 70% is the knowledge of the technology to monitor and 30% is the Splunk knowledge.

I don't know which firewall technologies you have, probably someone of them already have specific apps and you can start from them in your analysis, so try to search in splunkbase (apps.splunk.com) and define with your firewall specialists the Use Cases to implement.

Another ides is to use Google to search questions in our Community about your technologies.

If you need is instead how to search in your logs, Splunk share training and tutorials (some for free and some for a fee), these are some initial free examples:

https://docs.splunk.com/Documentation/Splunk/8.2.0/SearchTutorial/WelcometotheSearchTutorial

https://www.splunk.com/en_us/training/free-courses/splunk-fundamentals-1.html

and many videos on YouTube.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...