I'm reaching out to the Splunk community once again for some query help. I'm trying to find all the traffic going through my proxies, specifically the IPs and their geolocation. Does this seem feasible?
Thanks in advance!
You want to tack the iplocation command to the end the search that shows your traffic.
https://docs.splunk.com/Documentation/Splunk/6.5.2/SearchReference/Iplocation
That certainly helps, but I'm also looking for help with the query to find the information as well as tack on the geo-location options. Is there a specific search string that's used to find traffic going through a proxy?
That would be completely dependent on what your proxy log data looks like.