Splunk Search

How to create a search which shows machines being mined as opposed to staff visiting sites with the word "CoinHive" in them and how to get events which are actually effecting users?

DDewarSplunk
New Member

Good Morning

Out of interest I wondered if anyone had a Splunk Search, which clearly showed machines being mined as opposed to staff visiting sites with the word "CoinHive" in them?

I ran a search for CoinHive and came across a number of events , but I need to be more accurate in my searching to get events which are actually effecting users.

Can anyone suggest a search which will capture machines running the javaScript and so being effected ?

Thanks

David

0 Karma

stboch
SplunkTrust
SplunkTrust

What data are you collecting proxy logs? if so what type of proxy and does it record user agent strings?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...