Hi,
I'm pretty new to spluk,
I'm looking for some help with malware detection.
What would the search expression look like to detect beaconing activity from infected hosts?
my unknowns here would be "host" and "destination" since i have no idea what may be infected and with what malware.
Thanks.
you can bin _time and then count the number of bins that something appears in:
maybe something like eval foo = host + " : " + dest| bin _time span=1h |stats count foo AS concount by _time | stats value(concount) count by foo
This should give you the numbers of connections per hour and the number of hours that they occurred.