Getting Data In

Firewall Traffic

gharpe2
Explorer

I need a search to show the top 25 non-http and non-https services going out of my firewall. Does anyone have a search to pull this data. I need to list the protocol, port number and number of times it was accessed. In table format would be nice as well.

Tags (3)
0 Karma

Takajian
Builder

In general, "top" command is useful for your requirement. Please note that "top" command show just 10 results by default, but you can use limit option to show 25 results. The command will be like as bellow.

sourcetype= | top < your field2> limit=25

Please also refer to top command in manual.

http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/top

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...