Splunk Search

Can anyone help me determine if this is a threat to my system?

Szethius
Explorer

Trying to determine and get spun up on a lot of the terminology in splunk. So I have some events that I was lucky to find in the logs, potentially their source is threatening as an exploit. Can anyone help clarify what is going on with them? Much thanks!

See screenshot: http://i.imgur.com/0f4ZQca.png

Tags (1)
0 Karma

bigtyma
Communicator

This looks like a bot probing for vulnerabilities. For more information: http://forum.joomla.org/viewtopic.php?f=432&t=740054

If you have a Joomla site, make sure it is updated.

0 Karma

bosburn_splunk
Splunk Employee
Splunk Employee

Szethius - unfortunately we can't help you with determining what is a threat and what isn't a threat. If you're really concerned, you pretty much have two options. You can contact a professional security person to review your logs. The other option is to start Googling those log entries.

Brian

alacercogitatus
SplunkTrust
SplunkTrust

That IP address is registered in Turkey....... mmmmm... turkey.....

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...