Security

Find top IPs by # of unique ports attempted scan in FW logs

kevinlong206
New Member

Hi, another newbie question here.

I am analyzing firewall logs in this format:

Apr 4 22:03:18 10.20.10.1 Apr 4 22:05:47 X300 X300/FW_Activity: Info X300 type=FWD|proto=UDP|srcIF=p6|srcIP=174.61.183.230|srcPort=55555|srcMAC=66:66:01:58:04:18|dstIP=207.115.88.202|dstPort=55555|dstService=|dstIF=|rule=BLOCKALL|info=Block by Rule|srcNAT=0.0.0.0|dstNAT=0.0.0.0|duration=0|count=1|receivedBytes=0|sentBytes=0|receivedPackets=0|sentPackets=0|user=

I want to find the top 100 srcIPs BY how many # of unique dstPort the attempted to access, so I can find people who obviously portscanned my network.

something like "BLOCKALL | top 100 srcIP BY uniq dstPort
How can I find top srcIP by # of unique dstPort ?

Thank you!

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You could run this:

rule=BLOCKALL | stats dc(dstPort) as num_unique_ports by srcIP | sort - num_unique_ports | head 100
0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...