Dashboards & Visualizations

splunk dashboard searching

sam3655
New Member

on the splunk dashboard, is there a way to search for origin/source of a malware attack?

Tags (1)
0 Karma

sam3655
New Member

FireEye monitors our network and catches Malware Callbacks, I'm looking for a script tell me who sent the Malware?

0 Karma

lloydknight
Builder

Not very familiar with FireEye logs but logs can be pretty straightforward at most times. If source and destination IPs are visible in the logs, and you know what specific Malware attack to look up to then it's just a matter of identifying what time it occurred.

And if the source is not available in the logs, you'll just have to index the logs that contain the source (most likely firewall and network logs) then try to correlate it with the logs that contain the Malware attack.

Regarding the script that you're asking, you mean search query?

0 Karma

DalJeanis
SplunkTrust
SplunkTrust

Yes. NO. Maybe. It depends.

It depends on what you mean by "dashboard". It depends on what kind of attack. It depends on what your organization actually puts in splunk.

So, please update your question to be VERY specific.

We experienced an ABC attack, which
had THIS effect on our
organization/network/data.

What log data would we need to have
captured in order to determine the
source of the attack? What resources
are available in the splunk platform
to help us track that down?

0 Karma

lloydknight
Builder

your question is vague.

Assuming you're indexing logs containing the Malware attack and given that you know what type of attacks were executed on a certain time, yes, you can search that malware attack.

0 Karma

sam3655
New Member

is there a script for the search?

0 Karma

akocak
Contributor

are you looking at table or raw event data?
Moreover, origin in the sense of ip look lookup? Can you share more about what do you see?

thanks

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...