Splunk Search

Is there a way to identify/search what SMB version is being used across the network?

faizshir
Loves-to-Learn

Hello Splunkers,

Is there a way to identify/search what SMB version is being used across the network? I am looking to detect SMBv1 specifically to use it as a source for disabling SMBv1 throughout the network.

Regards

Labels (1)
Tags (1)
0 Karma

faizshir
Loves-to-Learn

Thanks Chaker. I have the STM app installed but I am unable to see any events within it. Would I be using the 'search & reporting' with stream as the sourcetype to view events, specifically to identify events with the details of SMB version in use.

Pardon me for being a noob.

0 Karma

chaker
Contributor

You could use the Splunk Stream App, it supports SMB as a filter.

https://docs.splunk.com/Documentation/StreamApp/8.1.0/DeployStreamApp/ProtocolDetection

The smb.dialect field contains the version.

https://docs.splunk.com/Documentation/StreamApp/8.1.0/DeployStreamApp/FileService

 

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...