Count of Attackers on Juniper Devices

The following is a Splunk search query that indicates potential “attacks” by source IP.  Further investigation will be needed to determine accuracy of attacks.

sourcetype = "juniper:idp" attack* | stats count by src_ip

Credit given to bbosearch.

Share This:

Leave A Comment?