Splunk Search

How to troubleshoot connectivity issues using Splunk?

trentsnowbarger
New Member

a customer reports intermittent connectivity issues to the internet, a website, what have you. Our instance of Splunk captures logs from our firewalls and other network devices. 
What are some search strings I would use, or how would I start using Splunk to troubleshoot historical (not live) connection issues going out to a website?

I know this is a broad question, but I'm just looking for some ideas on where to start. Thank you.

Labels (1)
0 Karma

smurf
Communicator

Hi,

first, I would look if a firewall dropped anything. So search the index with firewall logs for the user's IP address and the website's IP address, most likely port 80 or 443 since it is a website. I would do the same for any other network device like IPS/IDS. 

Hope this helps, at least a little.

smurf

0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...