Skip to main content
 
 
 
Splunk Lantern

Monitoring for network traffic volume outliers

 

You work for a small company and your manager wants you to put together a report on typical network usage among your users. Specifically, your manager is interested in which external websites network users most often communicate with.

You need to establish usage baselines and monitor them for anomalous behavior. You can use the stats command to perform a number of simple statistical calculations that give you a picture of traffic flows from your network hosts to external IP addresses. 

Data required 

Firewall data

How to use Splunk software for this use case

You can run many searches with Splunk software to establish baselines and set alerts. Depending on what information you have available, you might find it useful to identify some or all of the following: 

As you establish baselines, you might find source IP addresses that you want to investigate immediately. You can run the following investigations based off results from the monitoring activities in this use case:

Next steps

To maximize their benefit, the how-to articles linked in the previous section likely need to tie into existing processes at your organization or become new standard processes. These processes commonly impact success with this use case: 

  • Understanding cyclical usage patterns
  • Understanding network management policies 
  • Creating inventories of physical and virtual network devices
  • Creating network diagrams
  • Adhering to frameworks, such as the IT Infrastructure Library 

Measuring impact and benefit is critical to assessing the value of security operations. The following are example metrics that can be useful to monitor when implementing this use case:

  • Identification of risk factors: The number of anomalies you identified that were positive security risks

These additional Splunk resources might help you with this use case:

Splunk OnDemand Services: Use these credit-based services for direct access to Splunk technical consultants with a variety of technical services from a pre-defined catalog. Most customers have OnDemand Services per their license support plan. Engage the ODS team at ondemand@splunk.com if you would like assistance.