A HTTP response code profiling of the host making requests

The second job will help the analysts detect suspicious client behaviors with respect to the volume of requests per response code. Here are the steps to configure this job:

  1. Access the Machine Learning section in Kibana and create a new Advanced job on the NASA access logs index:

  1. Name the job in the Job Details panel:

  1. Finally, add the following detector in the Analysis Configuration panel, add response.keyword and clientip.keyword as influencers, and save the job:

  1. After running the job and accessing the Anomaly Explorer view, you should get results that are similar to the following ones:

  1. If you click on one of the red square anomalies, you will get the following details:

The preceding host has unusually high volumes of 200 and 404 response codes compared to the rest of the hosts.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.