Security

detect web application vulnerabilities

szone
Engager

hi

I want to detect web vulnerabilities for example "XSS" or " SQLI" with splunk. for this target i collect apache log into my splunk server. and till now I find match string with signature based rule for detect them and its implement with Regex in search app of splunk. so my question is there any other way to detect this vulnerabilities without app or with app (ex :Splunk Enterprise Security)?

thanks!

0 Karma

m_pham
Splunk Employee
Splunk Employee

Looks like you want scheduled searches - tweak as needed for your alert actions.

https://docs.splunk.com/Documentation/Splunk/latest/Search/Schedulingsearches

0 Karma

szone
Engager

thanks, but i have to write a app for detecting XSS attack with splunk.
can you help for it?

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...