Splunk Enterprise app Iris Enrich
Iris Enrich displays the latest enrichment data in an organized view and lets you manage monitored domains and tags.
For information on Iris Enrich, review the Iris Enrich API guide.
Threat Intelligence Dashboard
Section titled “Threat Intelligence Dashboard”The Threat Intelligence Dashboard is the primary landing page for the DomainTools app and displays the latest enrichment data. Select a value to get more detail on that statistic.
Interacting with the data
Section titled “Interacting with the data”Dashboards
Section titled “Dashboards”Click a panel’s value or domain to open the corresponding search query or enrichment explorer page within the applied time filter. Hover over a panel to reveal options to open it in search, export the individual value, or refresh the panel.
Threat map
Section titled “Threat map”Hover over each country to find the unique domain count with a geo-located IP associated with that country. You can also zoom using the plus and minus buttons on the map.
Time charts
Section titled “Time charts”The panels with numeric values provide two numbers to show the trend between the filtered timeline. The primary, large and bold, number is the current value while the smaller number, with the arrow, is the historical value from however long ago the time filter is set to, up to 60 days. The color and arrow direction of the historical value depend on whether the trend is desirable or undesirable, rather than larger or smaller. Regardless of whether the value went up or down, a green indicator represents a desirable trend (for example, fewer suspicious domains) and a red indicator represents an undesirable trend (for example, an increase in dangerous domains).
Filters
Section titled “Filters”The dashboard contains four filters that adjust the data available:
-
Filter
- A filter that accepts pre-created time values in minutes, hours, or days that adjusts how long ago to fetch data from.
-
Risky Observed Domains: Filter
- This filter affects the Risky Observed Domains graph and displays only the chosen risk factor.
- 100: Known Malicious
- 90-99: High
- 70-89: Medium
- 1-60: Low
- For more information, review Domain Risk Score.
- This filter affects the Risky Observed Domains graph and displays only the chosen risk factor.
-
Threat Map: Display
- This filter affects the Threat Map and only has two filters: Hosting IP and Registrant Country.
-
Auto Refresh Dashboard
- Enable or disable to change if the dashboard automatically refresh to pull new data. Refreshes happen at five minute intervals.
Enrichment data
Section titled “Enrichment data”The dashboard displays enrichment data in multiple formats: numeric values, graphs, tables, and a map.
- Unique Domains Observed
- Number of unique domains observed in your network being monitored within the DomainTools cache for the selected time period, compared to the previous time period.
- Dangerous Domains
- Uses a combination of the suspicious Risk Score threshold, threat profile, and domain age to determine a domain’s likelihood to be dangerous. Thresholds can be configured on the Configure Enrichment & Alerting settings page.
- The displayed value indicates the number of domains observed in the selected time period compared to the previous time period.
- Suspicious Domains
- Number of Domains with a DomainTools risk score higher than the configured Suspicious Risk Score threshold on the Configure Enrichment & Alerting settings page.
- The displayed value indicates the number of domains observed in the selected time period compared to the previous time period.
- Young Domains
- Number of Domains observed which were created within the young-domain window, based on the number of days set on the Configure Enrichment & Alerting settings page.
- The displayed value indicates the number of domains observed in the selected time period compared to the previous time period.
- Events Enriched
- Displays the total number of Events associated with domains enriched by DomainTools during the selected time period.
- Risky Observed Domains
- Graphs the number of events associated with domains observed in your network during the selected time period by DomainTools Risk Score levels.
- Thresholds are configurable on the Configure Enrichment & Alerting settings page.
- See Domain Risk Score for more information on Risk Score.
- Click a data point to view the underlying events.
- Newly Observed Domains
- The results show newly observed domains, risk score, the time and date that it has been first and last observed, and the number of events associated with that domain observed during the selected time period.
- Threat Map
- Maps the number of suspicious domains observed during the selected time period, based on the geolocation of their hosting IP or registrant country (configurable through filters). The Risk Score threshold for a suspicious event is configurable on the Enrichment & Alerting settings page.
- Threat Portfolio
- Plots the number of events associated with domains broken out by Threat Profile category over the selected time range. Click on a category in the legend to display the associated events.
- See Domain Risk Score for more information on Risk Score.
- Top 10 Tags From Cache
- Lists the top Iris Investigate Tags in use and the number of associated domains observed with that tag in the selected time period.
Monitoring Dashboard
Section titled “Monitoring Dashboard”The monitoring dashboard focuses on the enrichment data from monitored domains and tags, displaying the statistics in time charts and maps.
Interacting with the data
Section titled “Interacting with the data”Dashboards
Section titled “Dashboards”Click a panel’s value or domain to open the corresponding search query or enrichment explorer page within the applied time filter. Hover over a panel to reveal options to open it in search, export the individual value, or refresh the panel.
Threat map
Section titled “Threat map”Hover over each country to find the unique domain count with a geo-located IP associated with that country. You can also zoom using the plus and minus buttons on the map.
Time charts
Section titled “Time charts”The panels with numeric values provide two numbers to show the trend between the filtered timeline. The primary, large and bold, number is the current value while the smaller number, with the arrow, is the historical value from however long ago the time filter is set to, up to 60 days. The color and arrow direction of the historical value depend on whether the trend is desirable or undesirable, rather than larger or smaller. Regardless of whether the value went up or down, a green indicator represents a desirable trend (for example, fewer suspicious domains) and a red indicator represents an undesirable trend (for example, an increase in dangerous domains).
Filters
Section titled “Filters”The dashboard contains three filters that adjust the data available.
- Filter
- A filter that accepts pre-created time values in minutes, hours, or days that adjusts how long ago to fetch data from.
- Map
- This filter affects the Map and only has two filters: Hosting IP and Registrant Country.
- Auto Refresh Dashboard
- Enable or disable to change if the dashboard automatically refresh to pull new data.
Enrichment data
Section titled “Enrichment data”Like the threat intelligence dashboard, this dashboard displays data in multiple formats: numeric values, graphs, tables, and a map.
- Detected Domains
- Shows the number of domains detected within your network that are in the DomainTools Manage Monitored Domains (configurable under Monitoring). This includes any domains in the Allowlist.
- The displayed value indicates the number of domains observed in the selected time period compared to the previous time period.
- Tagged Suspicious Domains
- Suspicious Domains with an Iris Investigate Tag that are being monitored in Manage Monitored Tags, excluding any in the Allowlist. Tags and Allowlists are configurable under Monitoring. The Suspicious Domain Risk Score threshold is configurable under DT Settings.
- The displayed value indicates the number of domains observed in the selected time period compared to the previous time period.
- Iris Detect Domains Observed
- Domains discovered by DomainTools Iris Detect and observed in your network events. This includes any domains in the Allowlist.
- The displayed value indicates the number of domains observed in the selected time period compared to the previous time period.
- Total Alerts Generated
- Shows the number of alerts that were triggered within the selected time period, compared to the previous. Alerts are created based on rules set on the Configure Enrichment & Alerting settings page and can be triaged within Incident Review or by clicking on the number displayed.
- Total Events Monitored
- Shows the number of events associated with the domains detected within your network that are in the DomainTools Manage Monitored Domains (configurable under Monitoring). This includes any domains in the Allowlist.
- The displayed value indicates the number of events observed in the selected time period compared the previous time period.
- Currently Monitored
- Total number of Domains being monitored. This panel isn’t impacted by the dashboard time filter. Add domain monitors in Manage Monitored Domains (configurable under Monitoring).
- Suspicious Domains Over Time
- Shows a timeline of the suspicious domains observed over the filtered time period. Suspicious domains have a Risk Score at or above the Risk Threshold defined in the Configure Enrichment & Alerting settings page.
- Suspicious Domain Attribute Table
- Lists the domains observed with a Risk Score at or above the Risk Threshold defined in the Configure Enrichment & Alerting Settings page.
- Map
- Maps the number of unique domains observed in your environment based on the geolocation of the hosting IP or registrant country (configurable with the filters).
- DomainTools Alerts Over Time
- Shows a timeline of the unique alerts observed over the filtered time period. Alerts are created based on rules set on the Configure Enrichment & Alerting settings page.
- DomainTools Top Notable Events
- Displays the activity and status of DomainTools alerting rules within your environment. These can be configured on the Configure Enrichment & Alerting settings page.
Manage Monitored Domains
Section titled “Manage Monitored Domains”A centralized Monitoring List where you monitor domains manually or through DomainTools Iris Detect. Add domains to the monitoring list or remove them from it.
Options
Section titled “Options”- Enrich Monitored Domains
- Control how often monitored domains are enriched. Choose Only When Seen In The Event Log, Daily (every 24 hours), or Weekly (every 7 days).
- Add To Monitoring
- Add up to 100 comma separated domains, in SLD.TLD format, at a time.
- Source
- Determines which monitor list the domain is added to. Choose Current User, Iris Detect, or Enter Custom.
- Custom Source
- When Enter Custom is chosen in the previous option, enter your source here. If Enter Custom wasn’t selected, this field is grayed out.
- Remove From Monitoring
- If you need to remove certain domains from the monitoring list you can choose to do so as either a standalone action or while adding to the list. The list of actively monitored domains appears when clicking on the Select field and any number of domains may be selected for removal.
- Sync with Iris Detect Monitoring List
- When submitting changes, select this option to sync directly with the Iris Detect monitoring list. Any changes are then synced with your DomainTools account.
Monitoring List
Section titled “Monitoring List”The monitoring list is a table titled Monitoring List that contains the typical Iris Enrich output, sortable by field, with ten domains visible per page. Columns include Domain Name, Last Updated Date Time, Last Updated By, Added Date Time, Added By, Source, and Action.
Manage Monitored Tags
Section titled “Manage Monitored Tags”This app has the option to monitor any domains that associated with tags in DomainTools Iris investigation platform. Those Iris tags can be added to the monitored tags list for monitoring within Splunk.
Options
Section titled “Options”- Add Tags
- Add up to 100 comma separated Iris tags at a time. For information on Iris tags, refer to Iris Investigate Core Concepts
- Remove Tags
- If you need to remove certain tags from the monitoring list you can choose to do so as either a standalone action or while adding to the list. The list of actively monitored tags appears when clicking on the Select field and any number of tags may be selected for removal.
The table in this section displays information on the tags being monitored, with the columns Tag Being Monitored, Last Updated Date Time, Last Updated By, Added Date Time, Added By, and Action. The Action column removes the tag from the monitored list.
Related resources
Section titled “Related resources”- Iris Investigate — pull a domain’s current Iris Investigate profile and run guided pivots
- Iris Detect — triage new and changed domains from monitored terms
- Enrichment Explorer — search and filter enrichment data from the app cache
- DT Settings — configure enrichment, alerting, and monitored domains and tags