Splunk Search

How to create a real-time map of attacks

Shabalala9
New Member

I want to create a real-time map similar to https://cybermap.kaspersky.com/ that tracks and displays the exact location of where the attack came from?

Tags (1)
0 Karma

niketn
Legend

@Shabalala9 as far as you have source and destination ip address or geo-location you can use Missile Map Custom Visalization in Splunk.

You can also check out After Glow Visualization to map source and destination machine (not on Map though)

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...