All Apps and Add-ons

How does the Internal Spammers dashboard work in the Splunk App for Microsoft Exchange?

jmccreery
Explorer

There are three settings which can be modified in the dashboard but we haven't been able to find and definitions as to what exactly the parameters are related to and how they interact.

Minimum Messages (defaults to 80)
Message Rate (defaults to 80)
(Time)(defaults to All Time)

Opening the dashboard in a Search reveals this: 'internal-spammer'(80,80)'

1 Solution

jmccreery
Explorer

Finally found what I was looking for - Internal Spammers is a Macro requiring 2 Arguments. Now that I can see the search definition it makes a bit more sense.

View solution in original post

jmccreery
Explorer

Finally found what I was looking for - Internal Spammers is a Macro requiring 2 Arguments. Now that I can see the search definition it makes a bit more sense.

jmccreery
Explorer

Running the internal spammers with parameters (60,60) report for a time period of 60 minutes does this:

Has any account sent to more than 60 people in the previous 60 minutes?
If so, have they sent messages at a rate of more than 60 messages per minute?
If so, send an alert.

0 Karma

ppablo
Retired

Hi @jmccreery

If you could provide more insight on your understanding beyond the definition for folks who might still be in the dark about this, feel free to share 🙂

Patrick

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...