Skip to main content
Splunk Lantern

Detecting network and port scanning


Attackers scan networks for IP addresses and ports so they can find a good entry point into your organization. You want to see if scanning activity is coming from someone other than an authorized person internally.

​Data required

Firewall data

How to use Splunk software for this use case

Next steps

For more great content from the Splunk Education and Training team, check out Splunk How-To on YouTube or sign up for a course.

Still need help with this use case? Most customers have OnDemand Services per their license support plan. Engage the ODS team at if you require assistance.