Splunk Enterprise Security

Help with Suspect IP hits to my web.

satyaallaparthi
Communicator

Hello,
I have WEB IIS Logs.

we have IP addresses in the web logs and want to know when web hits from suspect IP's

I want to check our web data model events against known bad_IP addresses.

Anyone know where we can get a list of ip addresses from known bad actors. bots, hackers etc and How to Ingest in to SPLUNK and check.

Any help would be Appreciated!

Thanks,

0 Karma
1 Solution

satyaallaparthi
Communicator

Hello,

Do you have any idea about the threat feed data and to which index that data will go when ever the feed is done..

Thanks,

0 Karma

solarboyz1
Builder

It would depends. ThreatConnect, when using the Add-on, stored its data in kvstores, iSight used an index.

0 Karma

satyaallaparthi
Communicator

We will get some Pre built threat feeds in splunk ES.. right ?? When we Enable those feeds.. To Which index that data will go ?

Index = ioc ? or index = stix ? or index = threat_activity?

what is IOC(indicator of Compromise) format or STIX format ?

0 Karma

solarboyz1
Builder

The threat feeds configured via threat intelligence download in ES are put into kvstores, like service_intel, file_intel, ip_intel, etc..

You can view the data in them:
| inputlookup ip_intel

For more detail, Enterprise Security -> Security Intelligence -> Threat Intelligence -> Threat Artifacts. use the "open in search" icon to open the "threat overview" panel in search mode to see the search syntax and where that data is pulled from.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...