Splunk Enterprise Security

Enterprise Security - New Domain Analysis Dashbaord - Help with the WHOIS functionality

joshuamcqueen
Path Finder

Hey Splunkers,

Working on configuring Enterprise Security and need a hand with New Domain Analysis Dashboard. Here's whats up:

  • Under "Domain Type" when I select "Newly Seen" -- I see plenty of results and all but the bottom panel populate correctly.
  • Under "Domain Type" when I select "Newly Registered" -- none of the panels populate.

My hunch is that whatever mechanism that calls the "whois" doesn't work correctly. I went into "SA-NetworkProtection\bin" and chmoded all the python files to execute. Permissions look right.

The problem (I think) is that my ES search head has no internet access. Pretty sure I need to open up the mechanism that makes the whois work. Any advice on this? Documentation? Instructions?

As always, thanks in advance!

0 Karma

eric_budke
Path Finder

Search for "whois" at http://docs.splunk.com/Documentation/ES/3.2/Install/AdvancedThreatdashboards
You need to sign up for another service at domaintools at a minimum it looks like.

kskujawa
Explorer

Any luck with a fix?

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.