- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is there a way to identify/search what SMB version is being used across the network?
faizshir
Loves-to-Learn
10-07-2022
01:41 AM
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
faizshir
Loves-to-Learn
10-07-2022
02:33 AM
Thanks Chaker. I have the STM app installed but I am unable to see any events within it. Would I be using the 'search & reporting' with stream as the sourcetype to view events, specifically to identify events with the details of SMB version in use.
Pardon me for being a noob.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

chaker
Contributor
10-07-2022
01:57 AM
You could use the Splunk Stream App, it supports SMB as a filter.
https://docs.splunk.com/Documentation/StreamApp/8.1.0/DeployStreamApp/ProtocolDetection
The smb.dialect field contains the version.
https://docs.splunk.com/Documentation/StreamApp/8.1.0/DeployStreamApp/FileService
