Splunk Search

How to create a search which shows machines being mined as opposed to staff visiting sites with the word "CoinHive" in them and how to get events which are actually effecting users?

DDewarSplunk
New Member

Good Morning

Out of interest I wondered if anyone had a Splunk Search, which clearly showed machines being mined as opposed to staff visiting sites with the word "CoinHive" in them?

I ran a search for CoinHive and came across a number of events , but I need to be more accurate in my searching to get events which are actually effecting users.

Can anyone suggest a search which will capture machines running the javaScript and so being effected ?

Thanks

David

0 Karma

stboch
SplunkTrust
SplunkTrust

What data are you collecting proxy logs? if so what type of proxy and does it record user agent strings?

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...