Splunk Search

Is there a way to identify/search what SMB version is being used across the network?

faizshir
Loves-to-Learn

Hello Splunkers,

Is there a way to identify/search what SMB version is being used across the network? I am looking to detect SMBv1 specifically to use it as a source for disabling SMBv1 throughout the network.

Regards

Labels (1)
Tags (1)
0 Karma

faizshir
Loves-to-Learn

Thanks Chaker. I have the STM app installed but I am unable to see any events within it. Would I be using the 'search & reporting' with stream as the sourcetype to view events, specifically to identify events with the details of SMB version in use.

Pardon me for being a noob.

0 Karma

chaker
Contributor

You could use the Splunk Stream App, it supports SMB as a filter.

https://docs.splunk.com/Documentation/StreamApp/8.1.0/DeployStreamApp/ProtocolDetection

The smb.dialect field contains the version.

https://docs.splunk.com/Documentation/StreamApp/8.1.0/DeployStreamApp/FileService

 

0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...