Splunk Search

Network traffic for Windows Update (Firewall logs)

a_n
Path Finder

Hello,
I am checking a firewall log (Watchguard firebox) to monitor the network traffic for a windows LAN.
I need to filter out the network load related to Windows Updates.
The watchguard fields do not have sni in all records (sometime I have sni=download.microsoft.com, but sometimes sni is empty but destination IP is always available)

Is there a list of the IPs used for windows update?
( I did not manage to find it)
Is there another way to segregate the windows update traffic from other traffics?

Appreciate if you share your ideas.

Thank you.

Tags (1)
0 Karma

a_n
Path Finder

Hello,

Anyone can advise?

Thank you.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...