<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall Services Search in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Firewall-Services-Search/m-p/22704#M3530</link>
    <description>&lt;P&gt;Sample Events:&lt;/P&gt;

&lt;P&gt;9:36:33.000 AM  &lt;/P&gt;

&lt;P&gt;Nov 28 09:36:33 10.10.0.253 Nov 28 2011 10:36:33: %ASA-2-106001: Inbound TCP connection denied from 10.223.7.21/2999 to 109.13.183.81/445 flags SYN  on interface inside&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;host=10.10.0.253   Options|  
sourcetype=syslog   Options|  
source=udp:514   Options
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;2       11/28/11&lt;BR /&gt;
9:36:33.000 AM  &lt;/P&gt;

&lt;P&gt;Nov 28 09:36:33 10.10.0.253 Nov 28 2011 10:36:33: %ASA-2-106006: Deny inbound UDP from 62.192.232.25/54657 to 63.78.74.228/35731 on interface outside&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;host=10.10.0.253   Options|  
sourcetype=syslog   Options|  
source=udp:514   Options
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;3       11/28/11&lt;BR /&gt;
9:36:33.000 AM  &lt;/P&gt;

&lt;P&gt;Nov 28 09:36:33 10.10.0.253 Nov 28 2011 10:36:33: %ASA-2-106001: Inbound TCP connection denied from 10.222.7.13/3954 to 109.21.83.57/445 flags SYN  on interface inside&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;host=10.10.0.253   Options|  
sourcetype=syslog   Options|  
source=udp:514   Options
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Mon, 28 Nov 2011 15:37:53 GMT</pubDate>
    <dc:creator>gharpe2</dc:creator>
    <dc:date>2011-11-28T15:37:53Z</dc:date>
    <item>
      <title>Firewall Services Search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Firewall-Services-Search/m-p/22702#M3528</link>
      <description>&lt;P&gt;Need a search to list the top 25 non-http and non-https services people are connecting to through my ASA.  Does anyone have a search for that?  I would like to list the port, protocol and number of times connections were made.  &lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
glh&lt;/P&gt;</description>
      <pubDate>Sun, 27 Nov 2011 18:00:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Firewall-Services-Search/m-p/22702#M3528</guid>
      <dc:creator>gharpe2</dc:creator>
      <dc:date>2011-11-27T18:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Services Search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Firewall-Services-Search/m-p/22703#M3529</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Please provide a few samples events from your log. &lt;/P&gt;

&lt;P&gt;And also, please delete your duplicate forum post "Firewall Traffic". &lt;/P&gt;

&lt;P&gt;/kristian&lt;/P&gt;</description>
      <pubDate>Sun, 27 Nov 2011 20:11:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Firewall-Services-Search/m-p/22703#M3529</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2011-11-27T20:11:21Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Services Search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Firewall-Services-Search/m-p/22704#M3530</link>
      <description>&lt;P&gt;Sample Events:&lt;/P&gt;

&lt;P&gt;9:36:33.000 AM  &lt;/P&gt;

&lt;P&gt;Nov 28 09:36:33 10.10.0.253 Nov 28 2011 10:36:33: %ASA-2-106001: Inbound TCP connection denied from 10.223.7.21/2999 to 109.13.183.81/445 flags SYN  on interface inside&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;host=10.10.0.253   Options|  
sourcetype=syslog   Options|  
source=udp:514   Options
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;2       11/28/11&lt;BR /&gt;
9:36:33.000 AM  &lt;/P&gt;

&lt;P&gt;Nov 28 09:36:33 10.10.0.253 Nov 28 2011 10:36:33: %ASA-2-106006: Deny inbound UDP from 62.192.232.25/54657 to 63.78.74.228/35731 on interface outside&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;host=10.10.0.253   Options|  
sourcetype=syslog   Options|  
source=udp:514   Options
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;3       11/28/11&lt;BR /&gt;
9:36:33.000 AM  &lt;/P&gt;

&lt;P&gt;Nov 28 09:36:33 10.10.0.253 Nov 28 2011 10:36:33: %ASA-2-106001: Inbound TCP connection denied from 10.222.7.13/3954 to 109.21.83.57/445 flags SYN  on interface inside&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;host=10.10.0.253   Options|  
sourcetype=syslog   Options|  
source=udp:514   Options
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 28 Nov 2011 15:37:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Firewall-Services-Search/m-p/22704#M3530</guid>
      <dc:creator>gharpe2</dc:creator>
      <dc:date>2011-11-28T15:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall Services Search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Firewall-Services-Search/m-p/22705#M3531</link>
      <description>&lt;P&gt;Hi, while I do not completely understand your post, I can give the following example of a search , assuming that you have the following fields extracted (either manually or automatically)&lt;/P&gt;

&lt;P&gt;destination port :&lt;CODE&gt;dst_port&lt;/CODE&gt;;&lt;BR /&gt;
protocol: &lt;CODE&gt;proto&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;your_source/sourcetype&amp;gt; dst_port!="80" dst_port!="443" | stats count by dst_port proto | sort - count | head 25 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;hope this helps,&lt;/P&gt;

&lt;P&gt;Kristian&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2011 20:46:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Firewall-Services-Search/m-p/22705#M3531</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2011-11-28T20:46:00Z</dc:date>
    </item>
  </channel>
</rss>

