<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Search help in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-help/m-p/559327#M158917</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi All,&lt;/SPAN&gt;&lt;SPAN&gt;The following search has been created to identify the unsecure communications.&lt;/SPAN&gt;&lt;SPAN&gt;Also i need to see the end-to-end connectivity if it’s successful on unsecure protocol. For example, some services are configured in F5 with HTTP redirection profile. Now ultimately you will observe port 80 traffic on Edge firewall but F5 then redirects it to HTTPS.so please could you help us to achive these?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(index=paloalto OR index=juniper) (dest_port=&lt;/SPAN&gt; &lt;SPAN&gt;20 OR&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dest_port=&lt;/SPAN&gt; &lt;SPAN&gt;22 OR&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dest_port=&lt;/SPAN&gt; &lt;SPAN&gt;23 OR&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dest_port=&lt;/SPAN&gt; &lt;SPAN&gt;53 OR&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dest_port=&lt;/SPAN&gt; &lt;SPAN&gt;139 OR&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dest_port=&lt;/SPAN&gt; &lt;SPAN&gt;80 OR&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dest_port=&lt;/SPAN&gt; &lt;SPAN&gt;445 OR&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dest_port=&lt;/SPAN&gt; &lt;SPAN&gt;3389 OR&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dest_port=&lt;/SPAN&gt; &lt;SPAN&gt;21) | lookup Port_service.csv dest_port as dest_port OUTPUT service | stats count values(src_ip) by dest_port service dest_ip transport action&amp;nbsp; | table values(src_ip) dest_port service transport dest_ip count action&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 14 Jul 2021 13:15:52 GMT</pubDate>
    <dc:creator>vikkysplunk</dc:creator>
    <dc:date>2021-07-14T13:15:52Z</dc:date>
    <item>
      <title>Search help</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-help/m-p/559327#M158917</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi All,&lt;/SPAN&gt;&lt;SPAN&gt;The following search has been created to identify the unsecure communications.&lt;/SPAN&gt;&lt;SPAN&gt;Also i need to see the end-to-end connectivity if it’s successful on unsecure protocol. For example, some services are configured in F5 with HTTP redirection profile. Now ultimately you will observe port 80 traffic on Edge firewall but F5 then redirects it to HTTPS.so please could you help us to achive these?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(index=paloalto OR index=juniper) (dest_port=&lt;/SPAN&gt; &lt;SPAN&gt;20 OR&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dest_port=&lt;/SPAN&gt; &lt;SPAN&gt;22 OR&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dest_port=&lt;/SPAN&gt; &lt;SPAN&gt;23 OR&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dest_port=&lt;/SPAN&gt; &lt;SPAN&gt;53 OR&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dest_port=&lt;/SPAN&gt; &lt;SPAN&gt;139 OR&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dest_port=&lt;/SPAN&gt; &lt;SPAN&gt;80 OR&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dest_port=&lt;/SPAN&gt; &lt;SPAN&gt;445 OR&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dest_port=&lt;/SPAN&gt; &lt;SPAN&gt;3389 OR&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dest_port=&lt;/SPAN&gt; &lt;SPAN&gt;21) | lookup Port_service.csv dest_port as dest_port OUTPUT service | stats count values(src_ip) by dest_port service dest_ip transport action&amp;nbsp; | table values(src_ip) dest_port service transport dest_ip count action&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 13:15:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-help/m-p/559327#M158917</guid>
      <dc:creator>vikkysplunk</dc:creator>
      <dc:date>2021-07-14T13:15:52Z</dc:date>
    </item>
  </channel>
</rss>

