Ad slot: top

SPL

Count of Attackers on Juniper Devices

Description

Submitted by ItsJohnLocke

The following is a Splunk search query that indicates potential “attacks” by source IP.  Further investigation will be needed to determine accuracy of attacks.
3 8
sourcetype = "juniper:idp" attack* | stats count by src_ip
Credit given to bbosearch.

Comments

0 total

Be the first to comment on this SPL.

Leave a comment

You must log in to post a comment.

Ad slot: bottom