I have multiple servers running an application and I will like to see the destination IP address and destination port these servers are talking to through Splunk. Please bear with me I am new to Splunk.
The servers can be identified as SIBAxyzP=hostname.
Thanks,
Abassydo
I tried to use the string below but I got no result found. Please help and advise.
index=palo_alto hostname=SIBAxyzP src_ip=* | table src_ip dest_ip dest_port
Could you please post some sample log data? Not the search string you use, but some of the log data you have in Splunk.
Can we have some sample log entries?