<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunking bandwidth from GTA firewalls in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunking-bandwidth-from-GTA-firewalls/m-p/95198#M7448</link>
    <description>&lt;P&gt;or even&lt;/P&gt;

&lt;P&gt;dstname=10.1.11.103 OR src=10.1.11.103 | &lt;BR /&gt;
eval tbytes= rcvd + sent |&lt;BR /&gt;
timechart sum(tbytes)&lt;/P&gt;</description>
    <pubDate>Fri, 16 Mar 2012 21:39:51 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2012-03-16T21:39:51Z</dc:date>
    <item>
      <title>Splunking bandwidth from GTA firewalls</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunking-bandwidth-from-GTA-firewalls/m-p/95195#M7445</link>
      <description>&lt;P&gt;Hello. I'm completely new to splunking and a novice with this firewall.&lt;/P&gt;

&lt;P&gt;I'm pretty much trying to monitor bandwidth from a device in my network. I want a nice dashboard to show me this.&lt;/P&gt;

&lt;P&gt;So the search that i am using is basically starts like &lt;/P&gt;

&lt;P&gt;dstname=10.1.11.103 OR src=10.1.11.103&lt;/P&gt;

&lt;P&gt;But not sure what goes next. I'm super clueless and i apologize for this thanks.&lt;/P&gt;

&lt;P&gt;Here is a log entry, ip's ommited:&lt;/P&gt;

&lt;P&gt;Mar 16 14:36:09 10.1.11.1 Mar 16 14:36:09 id=firewall time="2012-03-16 18:36:09" fw="00000000" pri=5 msg="Accept inbound, NAT tunnel" cat_action=pass dstname=10.1.11.103 proto=https/tcp src=10.1.11.102 srcport=4023 nat=208.x.x.134 natport=443 dnat=10.1.11.1 dnatport=4023 dst=10.1.11.103 dstport=443 rule=3 duration=134 sent=1531 rcvd=12945 pkts_sent=11 pkts_rcvd=14&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:32:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunking-bandwidth-from-GTA-firewalls/m-p/95195#M7445</guid>
      <dc:creator>FiveRiversIT</dc:creator>
      <dc:date>2020-09-28T11:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunking bandwidth from GTA firewalls</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunking-bandwidth-from-GTA-firewalls/m-p/95196#M7446</link>
      <description>&lt;P&gt;I'm wondering if this syntax is correct: &lt;/P&gt;

&lt;P&gt;dstname=10.1.11.103 OR src=10.1.11.103 | timechart sum(rcvd)&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2012 18:58:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunking-bandwidth-from-GTA-firewalls/m-p/95196#M7446</guid>
      <dc:creator>FiveRiversIT</dc:creator>
      <dc:date>2012-03-16T18:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunking bandwidth from GTA firewalls</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunking-bandwidth-from-GTA-firewalls/m-p/95197#M7447</link>
      <description>&lt;P&gt;yes, that is exactly right. you can also do: &lt;CODE&gt;... | timechart sum(rcvd), sum(sent)&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2012 19:14:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunking-bandwidth-from-GTA-firewalls/m-p/95197#M7447</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2012-03-16T19:14:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunking bandwidth from GTA firewalls</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunking-bandwidth-from-GTA-firewalls/m-p/95198#M7448</link>
      <description>&lt;P&gt;or even&lt;/P&gt;

&lt;P&gt;dstname=10.1.11.103 OR src=10.1.11.103 | &lt;BR /&gt;
eval tbytes= rcvd + sent |&lt;BR /&gt;
timechart sum(tbytes)&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2012 21:39:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunking-bandwidth-from-GTA-firewalls/m-p/95198#M7448</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2012-03-16T21:39:51Z</dc:date>
    </item>
  </channel>
</rss>

