Splunk Search

Is there a way to identify/search what SMB version is being used across the network?

faizshir
Loves-to-Learn

Hello Splunkers,

Is there a way to identify/search what SMB version is being used across the network? I am looking to detect SMBv1 specifically to use it as a source for disabling SMBv1 throughout the network.

Regards

Labels (1)
Tags (1)
0 Karma

faizshir
Loves-to-Learn

Thanks Chaker. I have the STM app installed but I am unable to see any events within it. Would I be using the 'search & reporting' with stream as the sourcetype to view events, specifically to identify events with the details of SMB version in use.

Pardon me for being a noob.

0 Karma

chaker
Contributor

You could use the Splunk Stream App, it supports SMB as a filter.

https://docs.splunk.com/Documentation/StreamApp/8.1.0/DeployStreamApp/ProtocolDetection

The smb.dialect field contains the version.

https://docs.splunk.com/Documentation/StreamApp/8.1.0/DeployStreamApp/FileService

 

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...