I am trying to make a search for outbound traffic flow. i.e. source, destination IP and destination port. Is there any way to improve this search as it's currently breaking my search head and the performance is not as expected.
index=* sourcetype=* | stats values(dest_ip) values(dest_port) by src_ip
Your feedback and advice is much appreciated.
Thanks for the reply Sundaresh, I have used this query, since this is for firewall logs this query is using too long to execute the result. So I have to break down the time range. Do you have any suggestions based on index summary. The current query that I am using is
index=firewall sourcetype=* action="allowed" NOT destip="10...*" NOT destport="443" NOT destport="80" | sistats count by srcip destip destport
Any feedback on this would help me to work on my assigned engagements 🙂