Splunk Enterprise Security

Does Splunk ESS include correlation rules for malware activities?

Max
Engager

Does Splunk ESS include, out of the box - functionalities that do not require any additional installation, correlation rules and alert for malware (worm, virus, ecc...) activities?

Thanks in advance,

Max

0 Karma

hazekamp
Builder

maxlanzi,

We have several OOTB correlation searches that leverage data provided by your Antivirus/Malware solutions.

Endpoint - Host With Multiple Infections - Rule
Endpoint - Old Malware Infection - Rule
Endpoint - High Number of Hosts With Infection - Rule
Endpoint - High Number Of Infected Hosts - Rule
Endpoint - High Or Critical Priority Host With Malware - Rule
Endpoint - Recurring Malware Infection - Rule
Endpoint - Outbreak Observed - Rule

We also have a number of OOTB correlation searches that discover activity indicative of malware, but leverage other data sets such as Firewall/Proxy.

If you need a comprehensive list of correlation searches and descriptions, please contact Splunk Sales.

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...