Hello Splunk Community! I am brand new to Splunk and all it's glory and I've been tasked to try and show what is currently scanning our environment and any basic information that goes with that. We have all of our firewall logs flowing into Splunk currently. I've been researching some search queries online but I wanted to ask the community for your input and see what helpful add-ons or tips you can provide me in this task. Anything for internal, external scanning and potentially setting up an alert when a new host has reached a specific threshold for excessive scanning. Thank you for your time!
... View more