<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic ingest monitoring in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Traffic-ingest-monitoring/m-p/660108#M2563</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Connection metrics are logged by splunkd to metrics.log. To search metrics.log directly replace ... in the following search with a space-delimited list of your expected egress addresses:&lt;/P&gt;&lt;P&gt;index=_internal source=*metrics.log* host=idx-i-* group=tcpin_connections sourceIp IN (...)&lt;/P&gt;&lt;P&gt;The same data is also logged to the _metrics metrics index:&lt;/P&gt;&lt;P&gt;| mstats avg(spl.mlog.tcpin_connections._tcp_KBps) as KBps where index=_metrics group=tcpin_connections sourceIp IN (...) by sourceIp&lt;/P&gt;&lt;P&gt;You can use the search/jobs endpoint to run an asynchronous or blocking request to execute one of the search above. See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.0.2305/RESTREF/RESTsearch#search.2Fjobs" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/9.0.2305/RESTREF/RESTsearch#search.2Fjobs&lt;/A&gt;&amp;nbsp;for more information.&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 03:11:01 GMT</pubDate>
    <dc:creator>tscroggins</dc:creator>
    <dc:date>2023-10-09T03:11:01Z</dc:date>
    <item>
      <title>Traffic ingest monitoring</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Traffic-ingest-monitoring/m-p/659306#M2537</link>
      <description>&lt;P&gt;Hi to all,&lt;/P&gt;&lt;P&gt;I'm a newbee in Splunk and I need to check If the Splunk Cloud is receiving traffic form our network infrastructure. I have thought to do via API request but I don't find the url where to do the request.&lt;/P&gt;&lt;P&gt;Could anybody to send me where I can find documentation to do this??? Or how can I do this??&lt;/P&gt;&lt;P&gt;Thanks in advance!!&lt;/P&gt;&lt;P&gt;David.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2023 14:15:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Traffic-ingest-monitoring/m-p/659306#M2537</guid>
      <dc:creator>Babi2002</dc:creator>
      <dc:date>2023-10-02T14:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic ingest monitoring</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Traffic-ingest-monitoring/m-p/660108#M2563</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Connection metrics are logged by splunkd to metrics.log. To search metrics.log directly replace ... in the following search with a space-delimited list of your expected egress addresses:&lt;/P&gt;&lt;P&gt;index=_internal source=*metrics.log* host=idx-i-* group=tcpin_connections sourceIp IN (...)&lt;/P&gt;&lt;P&gt;The same data is also logged to the _metrics metrics index:&lt;/P&gt;&lt;P&gt;| mstats avg(spl.mlog.tcpin_connections._tcp_KBps) as KBps where index=_metrics group=tcpin_connections sourceIp IN (...) by sourceIp&lt;/P&gt;&lt;P&gt;You can use the search/jobs endpoint to run an asynchronous or blocking request to execute one of the search above. See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.0.2305/RESTREF/RESTsearch#search.2Fjobs" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/9.0.2305/RESTREF/RESTsearch#search.2Fjobs&lt;/A&gt;&amp;nbsp;for more information.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 03:11:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Traffic-ingest-monitoring/m-p/660108#M2563</guid>
      <dc:creator>tscroggins</dc:creator>
      <dc:date>2023-10-09T03:11:01Z</dc:date>
    </item>
  </channel>
</rss>

