All Apps and Add-ons

How to filter by port number?

Tyler
Explorer

For instance, I want to filter for HTTP from 192.168.0.100. The closest I can get:

 

remoteAddress = 192.168.0.100
protocol = tcp

 

Is there no way to include the port?

https://docs.splunk.com/Documentation/Splunk/8.2.4/Admin/Inputsconf#Windows_Host_Monitoring

Labels (3)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...