Splunk Search

Splunk query to find IP attack in Geo Map

alexspunkshell
Contributor

 index=graphsecurityalert having information's about all attacks in "title" field

index=zscaler having information's about all IP & location  but it don't have logs about attacks.

Now i want query to find in geo map with IP and title of the attack.

i tried index=graphsecutity OR index=zscaler title=* | iplocation src_ip | geostats count by userStates{}.logonLocation  but i am unable to get results.

 

Please help me with query to find IP attacks in geo map

@soutamo @saravanan90 @thambisetty @ITWhisperer @gcusello @bowesmana   @to4kawa 

Labels (2)
0 Karma

tscroggins
Influencer

@alexspunkshell 

Can you provide sanitized sample events? I'm assuming you want to join Microsoft Graph Security API Add-On for Splunk events with Zscaler Technical Add-On for Splunk events.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...