Splunk Enterprise Security

Help with query to find out activity towards a particular URL

cyber_Maddy
Engager

query to find out activity towards a particular URL

eg: URL - https://www.microsoft.com/en-us/security

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What events do you have available to search?

What sort of activity are you trying to discover?

0 Karma

cyber_Maddy
Engager

There is a malicious website Eg: https://xxxx.xxxx.com

I just wanted to find out if anybody tried to access the URLhttps://xxxx.xxxx.com  from my organization or any communication from the malicious URL https://xxxx.xxxx.com to our network.

Firewall , Crowdstrike - are the available data

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...