Getting Data In

Firewall Traffic

gharpe2
Explorer

I need a search to show the top 25 non-http and non-https services going out of my firewall. Does anyone have a search to pull this data. I need to list the protocol, port number and number of times it was accessed. In table format would be nice as well.

Tags (3)
0 Karma

Takajian
Builder

In general, "top" command is useful for your requirement. Please note that "top" command show just 10 results by default, but you can use limit option to show 25 results. The command will be like as bellow.

sourcetype= | top < your field2> limit=25

Please also refer to top command in manual.

http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/top

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...