Detect Web Traffic To Dynamic Domain Providers
Description
This search looks for web connections to dynamic DNS providers.
Content Mapping
This content is not mapped to any local saved search. Add mapping
Help |
---|
Detect Web Traffic To Dynamic Domain Providers HelpThis search requires you to be ingesting web-traffic logs. You can obtain these logs from indexing data from a web proxy or by using a network-traffic-analysis tool, such as Bro or Splunk Stream. The web data model must contain the URL being requested, the IP address of the host initiating the request, and the destination IP. This search also leverages a lookup file, |
Search |
---|
Open in Search |