Hacker News new | past | comments | ask | show | jobs | submit login

Only raw logs. Splunk resolves IP to Country/Region/City (and geo coordinates if wanted to map these).

Mostly playing with raw logs and then even RAW-er logs using Splunk Stream (thing that switches network interface in promiscuous mode and gives me all data for all protocols and any context I ever want).

For example I can analyze anomalies in web hits and anomalies in web session to discover new, previously unknown traffic sources and patterns.

It helped to discover 2 new classes of cyberattacks I didn't know were targeting my server.




Sounds really useful. I'll have to check that out.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: