Splunk Enterprise Security

Splunk Telecommunication App to ingest RADIUS Account START|STOP record

lionel_orishane
New Member

Hi there,

I have a scenario that we are trying to design for a Telco to improve on overall IP/MSISDN subscriber reputation with Executive Summary or reporting.

a. For 2G/3G/4G mobile networks, subscriber ID = MSISDN – using SGSN, GGSN & HLR.
i. An MSISDN is the number associated with a SIM card
ii. Usually stored in Calling-Station-Id RADIUS attribute

b. For ADSL networks, subscriber ID = ADSL modem login – using the DSLAM & HLR
i. The login ID uniquely identifies the ADSL connection
ii. Usually stored in User-Name RADIUS attribute

We are hoping the SPLUNK Enterprise and Telecommunication App would have capability to retrieve the Calling-Station-Id and the Framed-IP-Address attributes from the START accounting record to update its local (SQL)table - as displayed by the RADIUS capture Attached:

For 2G/3G/4G/5Gsubscribers, the RADIUS server natively uses the Calling-Station-Id to store the subscriber ID (= the MSISDN number).

Then an AntiSpam solution can be configured to block the Outbound SPAM emails then share this blocked detection logs with DDEI via Syslog.

There's expected to be a concise correlation and reporting from the SIEM on the following. Detection by IP - MSISDN - Number of Spam detection - Sender Email ID - Recipient Email ID - Timestamp of Last event. There should be capability to drill down or further on this as well.

kindly advise or guide if this splunk App inherently has such capability explained above.

Regards,
Lionel

0 Karma

anortrup_splunk
Splunk Employee
Splunk Employee

For clarity, this question does not pertain to Splunk Investigate.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...