Splunk Search

will splunk do this for me?

jjj0923
New Member

I am planning on installing snort of my network to gather ip traffic. I would like to use splunk to show me graphically how much traffic each of the ip addresses on my network are generating and then to also establish to boundaries where I can be warned when either innbound or outbound traffic to and from selected ip addresses exceeds certain thresholds.

can splunk do this with snort reporting data?

thanks in advance.

Tags (1)
0 Karma

southeringtonp
Motivator

Snort is really the wrong tool for the job. Snort is an IDS; it's not a bandwidth/traffic monitor.

If you want to report and alert on numbers of intrusion detection alerts, then yes, you can do that.

If you want to report and alert on traffic utilization, then you'll need firewall logs, netflow information, or some other source that includes this type of data. Once you have the raw data, Splunk can help with the reporting.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...