Splunk Enterprise Security

Help with query to find out activity towards a particular URL

cyber_Maddy
Engager

query to find out activity towards a particular URL

eg: URL - https://www.microsoft.com/en-us/security

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What events do you have available to search?

What sort of activity are you trying to discover?

0 Karma

cyber_Maddy
Engager

There is a malicious website Eg: https://xxxx.xxxx.com

I just wanted to find out if anybody tried to access the URLhttps://xxxx.xxxx.com  from my organization or any communication from the malicious URL https://xxxx.xxxx.com to our network.

Firewall , Crowdstrike - are the available data

0 Karma
Get Updates on the Splunk Community!

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...