Splunk Enterprise

How to search destination ip address and destination port of an application running on multiple servers.

abassydo2018
Explorer

I have multiple servers running an application and I will like to see the destination IP address and destination port these servers are talking to through Splunk. Please bear with me I am new to Splunk.
The servers can be identified as SIBAxyzP=hostname.

Thanks,
Abassydo

Tags (1)
0 Karma

abassydo2018
Explorer

I tried to use the string below but I got no result found. Please help and advise.

index=palo_alto hostname=SIBAxyzP src_ip=* | table src_ip dest_ip dest_port

0 Karma

xpac
SplunkTrust
SplunkTrust

Could you please post some sample log data? Not the search string you use, but some of the log data you have in Splunk.

0 Karma

somesoni2
Revered Legend

Can we have some sample log entries?

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...