Splunk Enterprise Security

Can Splunk Dashboard draw a GEO Attack Graph ?

briansylaw
New Member

As title ,
Did anyone know how to plot alt textsuch attack graph in splunk?
Can Splunk Dashboard draw a GEO Attack Graph ? alt text
alt text

I know there is a query like this, alt text
FW blocked log | iplocation src_ip | geostats count as TOTAL
but this cannot display the relationship between source and destination .
I need a arrow vector to display the direction which likes the picture i have uploaded.

thanks
regards
Max

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Download and install the "Missile Map" app (https://splunkbase.splunk.com/app/3511/). Then see the documentation in the app's README.txt file. I used this app years ago, but don't remember any of the details.

---
If this reply helps you, Karma would be appreciated.
0 Karma

briansylaw
New Member

I could find a splunk app called "Missile Map"
https://splunkbase.splunk.com/app/3511/

Did anyone know how to use it ?

Many Thanks

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...