Splunk Search

How to create a search which shows machines being mined as opposed to staff visiting sites with the word "CoinHive" in them and how to get events which are actually effecting users?

DDewarSplunk
New Member

Good Morning

Out of interest I wondered if anyone had a Splunk Search, which clearly showed machines being mined as opposed to staff visiting sites with the word "CoinHive" in them?

I ran a search for CoinHive and came across a number of events , but I need to be more accurate in my searching to get events which are actually effecting users.

Can anyone suggest a search which will capture machines running the javaScript and so being effected ?

Thanks

David

0 Karma

stboch
SplunkTrust
SplunkTrust

What data are you collecting proxy logs? if so what type of proxy and does it record user agent strings?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...