Splunk Search

How to search for firewall data showing source ip, source port, destination ip, and destination port in tabular form?

Explorer

Hello,

I am new to Splunk and I need to get a report showing Firewall transactions with source IP and source port, destination IP and destination port in a table format.
Please help and advice

0 Karma
1 Solution

Builder

Something like:

index=firewall | stats count by src, dest, dest_port, src_port

View solution in original post

0 Karma

Builder

Something like:

index=firewall | stats count by src, dest, dest_port, src_port

View solution in original post

0 Karma

Explorer

Thank you so much. You rock

0 Karma

Explorer

It works. Thank you

0 Karma