Splunk Enterprise

How to search destination ip address and destination port of an application running on multiple servers.

abassydo2018
Explorer

I have multiple servers running an application and I will like to see the destination IP address and destination port these servers are talking to through Splunk. Please bear with me I am new to Splunk.
The servers can be identified as SIBAxyzP=hostname.

Thanks,
Abassydo

Tags (1)
0 Karma

abassydo2018
Explorer

I tried to use the string below but I got no result found. Please help and advise.

index=palo_alto hostname=SIBAxyzP src_ip=* | table src_ip dest_ip dest_port

0 Karma

xpac
SplunkTrust
SplunkTrust

Could you please post some sample log data? Not the search string you use, but some of the log data you have in Splunk.

0 Karma

somesoni2
Revered Legend

Can we have some sample log entries?

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...