We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 64109ee commit 690c286Copy full SHA for 690c286
Signatures/Splunk/panorama-src_ip-dest_port-spike.md
@@ -1,4 +1,4 @@
1
-index=pan_logs sourcetype=pan:traffic earliest=-1h
+index=pan_logs sourcetype=pan:traffic action=allowed earliest=-1h
2
| stats dc(dest_port) as dest_port_count by index, src_ip
3
| where dest_port_count > 100
4
| table index, src_ip, dest_port_count
0 commit comments