Splunk Enterprise Security

Wildcard for domain search

johnde
New Member

I am trying to find the domain that came in the logs but were faked to look similar for our domain.
So if my domain is abc.co I would like to list all entries that came for abc.co.xyz.com, abc.co.aaa.com, etc.
Thanks!

0 Karma

woodcock
Esteemed Legend

Can't you just do myfield=abc.co*? Also, check out this app:
https://splunkbase.splunk.com/app/3376/

0 Karma

koshyk
Super Champion

Please provide sample data for this. You can write the SPL in 1000's of ways if you don't provide sample data

0 Karma

johnde
New Member

Thanks for the reply @koshyk .
I am new to SPL and still trying to figure out the right approach, what I am trying to find out is if someone faked our login page and redirected a user when they login with their credentials to our page.
Let's say our login page is is login.mydomain.co and someone created a sub-domain with our login page name, login.mydomain.co.fakedomain.com and this looks similar to our login page. Once a user enters the username password they are redirected to mydomain.co. I wanted to see if any of our users clicked on that link and entered the credentials based on the redirect.
fakedomain.com is not constant and it can be any value.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...