Splunk Search

Is there a way to identify/search what SMB version is being used across the network?

faizshir
Loves-to-Learn

Hello Splunkers,

Is there a way to identify/search what SMB version is being used across the network? I am looking to detect SMBv1 specifically to use it as a source for disabling SMBv1 throughout the network.

Regards

Labels (1)
Tags (1)
0 Karma

faizshir
Loves-to-Learn

Thanks Chaker. I have the STM app installed but I am unable to see any events within it. Would I be using the 'search & reporting' with stream as the sourcetype to view events, specifically to identify events with the details of SMB version in use.

Pardon me for being a noob.

0 Karma

chaker
Contributor

You could use the Splunk Stream App, it supports SMB as a filter.

https://docs.splunk.com/Documentation/StreamApp/8.1.0/DeployStreamApp/ProtocolDetection

The smb.dialect field contains the version.

https://docs.splunk.com/Documentation/StreamApp/8.1.0/DeployStreamApp/FileService

 

0 Karma
Get Updates on the Splunk Community!

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

AI Adoption Hub Launch | Curated Resources to Get Started with AI in Splunk

Hey Splunk Practitioners and AI Enthusiasts! It’s no secret (or surprise) that AI is at the forefront of ...