Splunk Enterprise

How to search destination ip address and destination port of an application running on multiple servers.

abassydo2018
Explorer

I have multiple servers running an application and I will like to see the destination IP address and destination port these servers are talking to through Splunk. Please bear with me I am new to Splunk.
The servers can be identified as SIBAxyzP=hostname.

Thanks,
Abassydo

Tags (1)
0 Karma

abassydo2018
Explorer

I tried to use the string below but I got no result found. Please help and advise.

index=palo_alto hostname=SIBAxyzP src_ip=* | table src_ip dest_ip dest_port

0 Karma

xpac
SplunkTrust
SplunkTrust

Could you please post some sample log data? Not the search string you use, but some of the log data you have in Splunk.

0 Karma

somesoni2
Revered Legend

Can we have some sample log entries?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...