Splunk Search

Global Threat Landscape App help

hartfoml
Motivator

I am useing the Global Threat Landscape (GTL) app and like it

I wan to build a report that shows any of the IP's on the IP_Watchlist that have contacted my firewall. I would like to see this type of report.

top 10 Offending_IP, Country, Destination_IP, Destination_DNS_Name, Firewall_Action

My question is how do I use the GTL offending_ip and country lookup info to search my firewall logs for connection state?

Tags (1)
0 Karma
1 Solution

joshd
Builder

Change the permissions of the app so the "Sharing for config file-only objects" is set to "All apps" .. then all the other apps will be able to see what's available in that specific app.

View solution in original post

0 Karma

joshd
Builder

Change the permissions of the app so the "Sharing for config file-only objects" is set to "All apps" .. then all the other apps will be able to see what's available in that specific app.

0 Karma

ashari
Explorer

It does not work i.e. I cant see the fields of the ip watch list when I run a search with other indexers.

0 Karma

hartfoml
Motivator

Thats a good start thanks I'll let you know if I figure it out.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...