AbuseIPDB Check

Splunk Community

AbuseIPDB Check

AbuseIPDB Check
This app provides the custom command 'abuseip' - which will take a given IP address field, and enrich your data with various fields in the Abuse database, including CountryName, Domain, ISP, LastReportedAt, and AbuseConfidence (percentage). This can be used for alerting on high abuse confidence IP's and more. Usage: Copy the config.json file from this app's default directory, to this app's local directory and replace yourkeyhere with your AbuseIPDB API key. Requires a valid API key which can be acquired for free with an account: https://abuseipdb.com Please check out the GitHub page for more information and documentation: https://github.com/snags141/AbuseIPDB_check
1 topic and 0 replies mentioned AbuseIPDB Check in
Latest Topics
Latest Replies
No posts to display.
Top Topics
My Topics
No posts to display.