Splunk Search

Could you kindly assist me?

KingUs80
Loves-to-Learn Lots

I'm looking to craft a query  (a correlation search) that would trigger an alert in the event that an internal system tries to access a malicious website. I would greatly appreciate any suggestions you may have. Thank you in advance for your help.

Source=bluecoat

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @KingUs80 ,

see in the Splunk Security Essentials App (https://splunkbase.splunk.com/app/3435), or, if you already have, in Enterprise Security Premium App.

The feature in ES is Threat Intelligence: you must have an internal list of malicious sites of a list downloaded from free or payment services.

Other apps that you could use are MISP42 (https://splunkbase.splunk.com/app/4335) or https://splunkbase.splunk.com/apps?keyword=threat+intelligence 

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...