Comments

  1. Pradeep

    | tstats allow_old_summaries=true distinct_count(All_Traffic.dest_port) as ports from datamodel=Network_Traffic.All_Traffic where
    [ inputlookup internal_ip_range]
    [| inputlookup whitelist.csv WHERE RuleName=portscan
    | fields – RuleName, description
    | format “” “NOT (” “AND” “” “)” “)”] by All_Traffic.src_ip
    | search ports > 500
    | drop_dm_object_name("All_Traffic")

Leave A Comment?