Splunk Enterprise Security

Can Splunk Dashboard draw a GEO Attack Graph ?

briansylaw
New Member

As title ,
Did anyone know how to plot alt textsuch attack graph in splunk?
Can Splunk Dashboard draw a GEO Attack Graph ? alt text
alt text

I know there is a query like this, alt text
FW blocked log | iplocation src_ip | geostats count as TOTAL
but this cannot display the relationship between source and destination .
I need a arrow vector to display the direction which likes the picture i have uploaded.

thanks
regards
Max

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Download and install the "Missile Map" app (https://splunkbase.splunk.com/app/3511/). Then see the documentation in the app's README.txt file. I used this app years ago, but don't remember any of the details.

---
If this reply helps you, Karma would be appreciated.
0 Karma

briansylaw
New Member

I could find a splunk app called "Missile Map"
https://splunkbase.splunk.com/app/3511/

Did anyone know how to use it ?

Many Thanks

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...