Splunk Inc.
Performing rule-based actions for newly observed domain names

Last updated:

Abstract:

Domain names are determined for each computational event in a set, each event detailing requests or posts of webpages. A number of events or accesses associated with each domain name within a time period is determined. A registrar is further queried to determine when the domain name was registered. An object is generated that includes a representation of the access count and an age since registration for each domain names. A client can interact with the object to explore representations of domain names associated with high access counts and recent registrations. Upon determining that a given domain name is suspicious, a rule can be generated to block access to the domain name.

Status:
Grant
Type:

Utility

Filling date:

31 Jan 2020

Issue date:

31 Aug 2021