Splunk Dev

Datasets: Bruteforce and internal scanning

bouncingbubble
New Member

Hi I'm very new to splunk and would like to setup a demo and show how brute force attacks and internal network scanning is being detected by splunk.

I will use this tutorial: https://www.youtube.com/watch?v=x78lcsWPPW8 and

I'm looking for one dataset of a brute force attack and one dataset of internal network scanning, I want to import those datasets.
(Not live data)

Where can I find such datasets?

0 Karma

to4kawa
Ultra Champion

Please tell me what you did later.

0 Karma

alonsocaio
Contributor

I tried to find some specific datasets for scan attacks and brute force, maybe some of the following will help you.

https://www.unb.ca/cic/datasets/ids-2017.html
https://www.secrepo.com/

There is also some datasets from Splunk Boss of the SOC ctf, which contains a lot of security related logs:
https://github.com/splunk/botsv1
https://github.com/splunk/botsv2

If you want or need to generate real-time events you can try the Eventgen app:
https://splunkbase.splunk.com/app/1924/

Also, I would suggest you to try generating your own datasets, since some of those logs are not hard to get, as an example, Windows authentication events can be collected directly from your workstation, and to use the query in the video a small amount of logs would be enough.

Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...