Data Source: Splunk Stream TCP
Description
Logs TCP traffic captured by Splunk Stream, including details about source and destination IPs, ports, connection states, and packet-level metadata.
Details
| Property | Value |
|---|---|
| Source | stream:tcp |
| Sourcetype | stream:tcp |
Related Detections
| Name | Technique | Type |
|---|---|---|
| Cisco Smart Install Oversized Packet Detection | Exploit Public-Facing Application | TTP |
| Cisco Smart Install Port Discovery and Status | Exploit Public-Facing Application | TTP |
Supported Apps
- Splunk Add-on for Stream Wire Data (version 8.1.6)
Source: GitHub | Version: 2