Splunk Search

will splunk do this for me?

jjj0923
New Member

I am planning on installing snort of my network to gather ip traffic. I would like to use splunk to show me graphically how much traffic each of the ip addresses on my network are generating and then to also establish to boundaries where I can be warned when either innbound or outbound traffic to and from selected ip addresses exceeds certain thresholds.

can splunk do this with snort reporting data?

thanks in advance.

Tags (1)
0 Karma

southeringtonp
Motivator

Snort is really the wrong tool for the job. Snort is an IDS; it's not a bandwidth/traffic monitor.

If you want to report and alert on numbers of intrusion detection alerts, then yes, you can do that.

If you want to report and alert on traffic utilization, then you'll need firewall logs, netflow information, or some other source that includes this type of data. Once you have the raw data, Splunk can help with the reporting.

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...