Splunk Search
Highlighted

Searching a port range

Communicator

How can i search for matches using a port range on an extracted field?

for example:

if i want all events in port range 512-514 and i have a field extracted as dest_ip

or a larger extension, how to search using ranges of values?

Tags (2)
Highlighted

Re: Searching a port range

Influencer

You can search for ranges like this:

sourcetype=mysourcetype myfield>=512 myfield<=514

Which will give you results for events with myfield values from 512 to 514.

View solution in original post

Highlighted

Re: Searching a port range

Engager

Could you provide an example?

0 Karma
Highlighted

Re: Searching a port range

Engager

I discovered another method to search for a range:
srcip IN (10.10., 10.20., 10.30.*)
or
dest
port IN (110, 111, 112, 113)
instead of
srcip=10.10.* OR srcip=10.20.* OR srcip=10.30.*
or
dest
port=110 OR destport=111 OR destport=112