Splunk Search

How do I check which major destinations generate the most logs on a specific firewall host?

renangomes
New Member

How do I check which major destinations generate the most logs on a specific firewall host = 10.22.44.254? I would like to know the correct command to know the main destinations and also how to filter without them, to know how much license I would save if I don't receive them?

Labels (1)
Tags (1)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@renangomes - You can use the below search:

index=<firewall index> host="10.22.44.254"
| top 10 dest

 

You can see the percentage and see your current license usage by this host and see X percentage of that license usage you will save.

(You can check the license usage by this host on Monitoring Consoles' Historic License Usage page.)

 

I hope this helps!!!

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...