How to do it...

Follow the steps in this recipe to create a lookup table of potentially malicious IP addresses:

  1. Log in to your Splunk server.
  2. Select the Operational Intelligence application.
  3. In the search bar, enter the following search over a time range of Last 7 days, and hit Enter or click on the search icon to execute the search:
index=main sourcetype="access_combined" status=403 | stats  count by clientip | eval suspect="1" | outputlookup  createinapp=true suspect_ips.csv
  1. A tabulated list of IPs that contain the three columns of clientip, count, and suspect will be displayed. Click on the Save as link and select Report:
  2. Enter cp07_suspect_ips ...

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.