# SIEM - Network scan

**URL:** <https://discuss.elastic.co/t/siem-network-scan/309691>\
**Category:** SIEM\
**Created:** [July 14, 2022, 10:01pm UTC](https://discuss.elastic.co/t/siem-network-scan/309691 "2022-07-14T22:01:21Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ldmontoya](https://avatars.discourse-cdn.com/v4/letter/l/49beb7/32.png) [@ldmontoya](https://discuss.elastic.co/u/ldmontoya)\
**Post date:** [July 14, 2022, 10:01pm UTC](https://discuss.elastic.co/t/siem-network-scan/309691/1 "2022-07-14T22:01:21Z")

</div>

Hi guys!

I'm setting up the SIEM feature on kibana and one of my use cases is to detect network scans using nmap or any other tool. After digging on the community I've found the following threshold rule:

Query: `event.category: (network or network_traffic) and not destination.ip: 127.0.0.1`

Group by: `source.ip, destination ip >= 1`  
Count: `destination.port >= 10`  
Timestamp override: `event.ingested`

Whenever I perform a network scan using nmap on my PC, the rule seems to detect the scan, the problem is that the results are being displayed as if I've scanned only a single IP address instead of the whole VLAN. also, when I perform the scan to a single IP address, it does not seems to detect it.

Any ideas of what it could be ? I've tried many different scenarios but the result is the same.

Has anyone faced something like this ?

PS: I've tried with a machine learning job as well but I'm not quite convinced with the results

Thanks.

---

<div class="post-metadata">

**Author:** ![jamesspi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesspi/32/24479_2.png) [@jamesspi](https://discuss.elastic.co/u/jamesspi)\
**Post date:** [July 15, 2022, 5:43pm UTC](https://discuss.elastic.co/t/siem-network-scan/309691/2 "2022-07-15T17:43:43Z")

</div>

Hi @ldmontoya ,

That rule you've set up is for a port scan, not network scan. It is designed to work when only one address is scanned for 10 or more ports.

if you want to change that to a network scan, you will need to add the `destination.ip` to the count field, not `destination.port`.

Count is performing a unique count - so keep that in mind for these type of rules. So, in the use case I described above, it would only trigger if a source IP is scanning/accessing 10 or more _unique_ destination IP addresses.

The `Group by` fields are just a standard count, not unique.

Hope this helps.

James

---

<div class="post-metadata">

**Author:** ![ldmontoya](https://avatars.discourse-cdn.com/v4/letter/l/49beb7/32.png) [@ldmontoya](https://discuss.elastic.co/u/ldmontoya)\
**Post date:** [July 21, 2022, 9:09pm UTC](https://discuss.elastic.co/t/siem-network-scan/309691/3 "2022-07-21T21:09:24Z")

</div>

Hello

Thank you for your suggestion, unfortunately somehow the rule is unable to detect the scan. I've been trying with different ways too.

Luis

---

<div class="post-metadata">

**Author:** ![rachel\_gomez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rachel_gomez/32/108615_2.png) [@rachel\_gomez](https://discuss.elastic.co/u/rachel_gomez)\
**Post date:** [July 22, 2022, 9:13am UTC](https://discuss.elastic.co/t/siem-network-scan/309691/4 "2022-07-22T09:13:47Z")

</div>

Network scanning is a procedure for identifying active devices on a network by employing a feature or features in the network protocol to signal devices and await a response.

Regards,  
Rachel Gomez

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 19, 2022, 9:14am UTC](https://discuss.elastic.co/t/siem-network-scan/309691/5 "2022-08-19T09:14:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
