Splunk Enterprise Security

Can Splunk Dashboard draw a GEO Attack Graph ?

briansylaw
New Member

As title ,
Did anyone know how to plot alt textsuch attack graph in splunk?
Can Splunk Dashboard draw a GEO Attack Graph ? alt text
alt text

I know there is a query like this, alt text
FW blocked log | iplocation src_ip | geostats count as TOTAL
but this cannot display the relationship between source and destination .
I need a arrow vector to display the direction which likes the picture i have uploaded.

thanks
regards
Max

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Download and install the "Missile Map" app (https://splunkbase.splunk.com/app/3511/). Then see the documentation in the app's README.txt file. I used this app years ago, but don't remember any of the details.

---
If this reply helps you, Karma would be appreciated.
0 Karma

briansylaw
New Member

I could find a splunk app called "Missile Map"
https://splunkbase.splunk.com/app/3511/

Did anyone know how to use it ?

Many Thanks

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...