Splunk Search

will splunk do this for me?

jjj0923
New Member

I am planning on installing snort of my network to gather ip traffic. I would like to use splunk to show me graphically how much traffic each of the ip addresses on my network are generating and then to also establish to boundaries where I can be warned when either innbound or outbound traffic to and from selected ip addresses exceeds certain thresholds.

can splunk do this with snort reporting data?

thanks in advance.

Tags (1)
0 Karma

southeringtonp
Motivator

Snort is really the wrong tool for the job. Snort is an IDS; it's not a bandwidth/traffic monitor.

If you want to report and alert on numbers of intrusion detection alerts, then yes, you can do that.

If you want to report and alert on traffic utilization, then you'll need firewall logs, netflow information, or some other source that includes this type of data. Once you have the raw data, Splunk can help with the reporting.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...