Splunk Search

How to create a search which shows machines being mined as opposed to staff visiting sites with the word "CoinHive" in them and how to get events which are actually effecting users?

DDewarSplunk
New Member

Good Morning

Out of interest I wondered if anyone had a Splunk Search, which clearly showed machines being mined as opposed to staff visiting sites with the word "CoinHive" in them?

I ran a search for CoinHive and came across a number of events , but I need to be more accurate in my searching to get events which are actually effecting users.

Can anyone suggest a search which will capture machines running the javaScript and so being effected ?

Thanks

David

0 Karma

stboch
SplunkTrust
SplunkTrust

What data are you collecting proxy logs? if so what type of proxy and does it record user agent strings?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...