Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Tor traffic search feeds

$
0
0
Hi All, I work with Datamodels, and trying to create search which will alert me about TOR communication. Having some issues with enrichment. Can somebody help. **| eval TOR="iblocklist_tor" | lookup ip_intel threat_key as TOR ip as All_Traffic.src_ip OUTPUT ip | where isnotnull(ip)** Having some issues with enrichment. Can somebody help?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>