Splunk Search
Highlighted

10 TCP ports accessed by unique clients

Explorer

I am trying to search List the top 10 TCP ports accessed by unique IPs

Labels (2)
Tags (1)
0 Karma
Highlighted

Re: 10 TCP ports accessed by unique clients

Contributor
index=firewall 
    [ search index=firewall 
    | top limit=10 dest_port 
    | table dest_port ] 
| stats values(dest_port) as "Top 10 Ports" count by src_ip

View solution in original post

0 Karma