<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there a way to search for internal to external traffic? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-search-for-internal-to-external-traffic/m-p/315670#M59068</link>
    <description>&lt;P&gt;Oh,  first cut, I'd want to ignore the proxy logs, assuming they are functioning as expected, and check everything else internal first.  Because, you know, our proxy servers are intended to carry external traffic, so one end will (almost) always be outside.&lt;/P&gt;</description>
    <pubDate>Tue, 18 Jul 2017 21:14:28 GMT</pubDate>
    <dc:creator>DalJeanis</dc:creator>
    <dc:date>2017-07-18T21:14:28Z</dc:date>
    <item>
      <title>Is there a way to search for internal to external traffic?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-search-for-internal-to-external-traffic/m-p/315668#M59066</link>
      <description>&lt;P&gt;Is there a way to search for internal to external traffic?&lt;/P&gt;

&lt;P&gt;The network I work on is pretty locked down and any internal ip attempting to connect to an external source or vice versa &lt;BR /&gt;
would be considered suspicious. The SIEM we use is broken at the moment so a quick fix would be to look at internal to external&lt;BR /&gt;
traffic through Splunk. I'm not an expert at Splunk and was wondering if something like this is possible. Maybe equate internal to source and external to destination?  Basically any query that could get me internal to external traffic. How could I search for internal hosts going to an external source?  &lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2017 18:17:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-search-for-internal-to-external-traffic/m-p/315668#M59066</guid>
      <dc:creator>bezotic</dc:creator>
      <dc:date>2017-07-18T18:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to search for internal to external traffic?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-search-for-internal-to-external-traffic/m-p/315669#M59067</link>
      <description>&lt;P&gt;Okay, I'm not at work so I can't pull the "obvious internal ips" straight off out of my head, but if you generate a list of internal IPs, then everything not on the list is external.  &lt;/P&gt;

&lt;P&gt;Create a lookup table, and for any event, pull the ips, do a lookup on each.  If not found, then alert.   (First just yourself, while developing, to find what you've forgotten.  After you've got it reasonably clean, then you can alert more broadly.   &lt;/P&gt;

&lt;P&gt;Rinse, repeat.  &lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2017 21:09:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-search-for-internal-to-external-traffic/m-p/315669#M59067</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-07-18T21:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to search for internal to external traffic?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-search-for-internal-to-external-traffic/m-p/315670#M59068</link>
      <description>&lt;P&gt;Oh,  first cut, I'd want to ignore the proxy logs, assuming they are functioning as expected, and check everything else internal first.  Because, you know, our proxy servers are intended to carry external traffic, so one end will (almost) always be outside.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2017 21:14:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-search-for-internal-to-external-traffic/m-p/315670#M59068</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-07-18T21:14:28Z</dc:date>
    </item>
  </channel>
</rss>

