Skip to content

App to extract web attack records from xml-reports generated by IPA's iLogScanner.

Notifications You must be signed in to change notification settings

a5hlynx/app_ilog-scanner

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

6 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

App for iLogScanner Report

App to extract web attack records from xml-reports generated by IPA's iLogScanner.

Installation

  1. Logon to your Splunk and go to "Manage Apps".
  2. Click either "Install app from file" or "Browse more apps".
  3. "Install app from file"
    • Upload this app's tar.gz, which you should have gotten either from splunkbase or github beforehand.
  4. "Browse More Apps"
    • Search this app using the keywords like "iLogScanner" or "IPA", and then follow the instruction shown in the modal.

Usage

Generate reports

The inputs to this app are supposed to be xml reports generated by IPA's iLogScanner. Below is an usage example of iLogScanner, which detects suspicious or malicious access from apache access log, and generates a report in the form of xml based upon the detection result.

 ./iLogScanner.sh mode=cui logtype=apache accesslog=path/to/access_log outdir=output reporttype=xml level=detail

Ingest the reports

  1. Prepare reports explained above.
  2. Put the reports under $SPLUNK_BASE/etc/apps/app_ilog-scanner/xml.
  3. Go "Settings" >> "Data inputs" >> "Files & Directories".
  4. Either Enable or Modify $SPLUNK_HOME/etc/apps/app_ilog-scanner/xml.
  5. Enable
    • Just click "Enable" for $SPLUNK_HOME/etc/apps/app_ilog-scanner/xml. The data will be indexized into main. Preparation is done, and no need to go through the next few steps.
  6. Modify
    • Click $SPLUNK_HOME/etc/apps/app_ilog-scanner/xml" to change the index, into which the data will be indexized. If it's changed, macro should also be modified accordingly.
  7. Go "Advanced search" >> "Search macros", and click "ilog"
  8. Modify definition to specify the index changed in the step 6.

About

App to extract web attack records from xml-reports generated by IPA's iLogScanner.

Resources

Stars

Watchers

Forks

Packages

No packages published