I noticed with splunk you can search subnets now. However I would like to search for all communications via my internal network to my external network. When doing something like this however it does not work.
src_ip=10.10.0.0/16 dest_ip!=10.10.0.0/16
This does not work. How would I correctly search for what I am seeking?
Perhaps make use of the cidrmatch function: * | where NOT cidrmatch("10.10.0.0/16", dest_ip) AND cidrmatch("10.10.0.0/16",src_ip)
That should work. What you could try is specify NOT dest_ip=10.10.0.0/16
instead, but that's rather for covering the case when no dest_ip exists at all.