Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How could i filter network firewall data using a filed value ?

$
0
0
Hello, I have a firewall that sends a lot of data, i would like to filter events using a specific field value (exemple whitelist field="value") my stanza is like this : [udp://516] connection_host = ip sourcetype = stonegate whitelist = deviceExternalId="value" This didn't work and i still get all of data. Any help please ? thanks

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>