Splunk Search

will splunk do this for me?

jjj0923
New Member

I am planning on installing snort of my network to gather ip traffic. I would like to use splunk to show me graphically how much traffic each of the ip addresses on my network are generating and then to also establish to boundaries where I can be warned when either innbound or outbound traffic to and from selected ip addresses exceeds certain thresholds.

can splunk do this with snort reporting data?

thanks in advance.

Tags (1)
0 Karma

southeringtonp
Motivator

Snort is really the wrong tool for the job. Snort is an IDS; it's not a bandwidth/traffic monitor.

If you want to report and alert on numbers of intrusion detection alerts, then yes, you can do that.

If you want to report and alert on traffic utilization, then you'll need firewall logs, netflow information, or some other source that includes this type of data. Once you have the raw data, Splunk can help with the reporting.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...