You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Splunk SPL规则问题:特定端口扫描检测无结果,求修正优化

修正后的SPL规则及优化建议

问题根源

原规则执行stats dc(destination_port)...聚合后,结果集中已不存在destination_port原始字段,因此where子句里的destination_port IN (...)条件无法匹配任何数据,导致无结果返回。

修正后的SPL规则

方案一(推荐,性能更优)

先过滤出目标端口为指定范围的事件,再统计不同端口数量:

index=network destination_port IN (20, 21, 23, 80, 443)
| stats dc(destination_port) as number_destination_port by source_ip destination_ip
| where number_destination_port > 100

方案二(适合需保留全量事件再做条件统计的场景)

在统计阶段仅计算指定端口的不同数量:

index=network
| stats dc(eval(if(destination_port IN (20,21,23,80,443), destination_port, null()))) as number_destination_port by source_ip destination_ip
| where number_destination_port > 100

优化建议

  • 提前过滤缩减数据量:在索引查询阶段就过滤目标端口,避免后续处理无关事件,大幅提升查询效率。
  • 限定时间窗口:端口扫描多为短时间内的行为,建议添加时间范围参数,比如earliest=-1h latest=now,精准定位近期扫描行为,减少误判。
  • 排除合法扫描源:如果存在内部已知的合法扫描IP(如运维扫描设备),可添加NOT source_ip IN (192.168.1.100, 10.0.0.5)排除,降低误报率。
  • 结合多维度指标:除了统计不同端口数,还可统计事件总数count、扫描持续时间max(_time)-min(_time),比如添加stats dc(destination_port) as number_destination_port count as total_requests min(_time) as start_time max(_time) as end_time by source_ip destination_ip,通过total_requests判断是否存在高频请求,end_time-start_time判断扫描的时间跨度,提升检测准确性。
  • 过滤无效数据:添加isnotnull(source_ip) AND isnotnull(destination_ip) AND source_ip != destination_ip,排除空IP或源目IP相同的无效事件。

内容的提问来源于stack exchange,提问作者Rémi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 19:20:11