AbuseIPDB App

Splunk Community

AbuseIPDB App

AbuseIPDB App
App is made with two functionalities, utilizing the report and check endpoints of the AbuseIPDB v2 API. One is to automatically report suspicious activities in configured logs to the AbuseIPDB API, by running saved searches and raising alerts to trigger action. The second functionality of the app is to provide a custom search command that allows the user to pass in an ip address, which will get programmatically checked against the AbuseIPDB API check endpoint, and return data such as the abuseConfidenceScore.
2 topics and 0 replies mentioned AbuseIPDB App in
Latest Topics
Latest Replies
No posts to display.
Top Topics
My Topics
No posts to display.