Splunk SPL规则问题:特定端口扫描检测无结果,求修正优化
修正后的SPL规则及优化建议
问题根源
原规则执行stats dc(destination_port)...聚合后,结果集中已不存在destination_port原始字段,因此where子句里的destination_port IN (...)条件无法匹配任何数据,导致无结果返回。
修正后的SPL规则
方案一(推荐,性能更优)
先过滤出目标端口为指定范围的事件,再统计不同端口数量:
index=network destination_port IN (20, 21, 23, 80, 443) | stats dc(destination_port) as number_destination_port by source_ip destination_ip | where number_destination_port > 100
方案二(适合需保留全量事件再做条件统计的场景)
在统计阶段仅计算指定端口的不同数量:
index=network | stats dc(eval(if(destination_port IN (20,21,23,80,443), destination_port, null()))) as number_destination_port by source_ip destination_ip | where number_destination_port > 100
优化建议
- 提前过滤缩减数据量:在索引查询阶段就过滤目标端口,避免后续处理无关事件,大幅提升查询效率。
- 限定时间窗口:端口扫描多为短时间内的行为,建议添加时间范围参数,比如
earliest=-1h latest=now,精准定位近期扫描行为,减少误判。 - 排除合法扫描源:如果存在内部已知的合法扫描IP(如运维扫描设备),可添加
NOT source_ip IN (192.168.1.100, 10.0.0.5)排除,降低误报率。 - 结合多维度指标:除了统计不同端口数,还可统计事件总数
count、扫描持续时间max(_time)-min(_time),比如添加stats dc(destination_port) as number_destination_port count as total_requests min(_time) as start_time max(_time) as end_time by source_ip destination_ip,通过total_requests判断是否存在高频请求,end_time-start_time判断扫描的时间跨度,提升检测准确性。 - 过滤无效数据:添加
isnotnull(source_ip) AND isnotnull(destination_ip) AND source_ip != destination_ip,排除空IP或源目IP相同的无效事件。
内容的提问来源于stack exchange,提问作者Rémi
相关产品推荐
相关产品推荐

