Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

correlate between tow sources

$
0
0
hi i have tow devices, i want to check the result of the same event in tow devices. for example if one source is blocked in one device on another device what is the action! Device A = fw=x.x.x.x msg=""Connection Closed" " appName=""General HTTP"" n=366680949 src=150.X.X.55:34884:X1 dst=192.168.x.x:80:X2 Device B = risk=None, event=""Other"", proxy=""://generic:"",, source=""150.X.X.55"", violation=""Invalid hostname"", path=""/"", method=""GET"", node=""WebApplicationFirewall"", action=""Block"" in device A the ip is connection closed and on the device b the ip is blocked tanx

Viewing all articles
Browse latest Browse all 47296

Trending Articles