All Apps and Add-ons

Need Linux equivalent query for network traffic stats

NK
Explorer

Using Splunk Add-on for Microsoft Windows, Splunk Add-on for Unix and Linux on Splunk Enterprise v9.3.0

What are the Linux (RHEL 8 ) equivalents for these Splunk Windows queries?

e.g. Network Traffic:

Windows:

index=wmi host=MyWindowsHost sourcetype="Perfmon:Network Interface" counter=Bytes* | timechart span=15m max(Value) as "Bytes/sec" by counter

Linux:
?

e.g. CPU: 

Windows:

index=wmi host=MyWindowsHost sourcetype="Perfmon:CPU Load" | timechart span=15m max(Value) as "CPU Load" by counter

Linux:

index=os host=MyLinuxHost source=cpu CPU="all" | timechart span=15m max(pctSystem),max(pctUser) by CPU
Labels (2)
Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @NK ,

I suppose that you're using the Splunk_TA_nix add-on to ingest the Linux logs, if not, use it!

You have to enable the [script://./bin/netstat.sh] input.

In this way, you'll have the same information of Windows.

Ciao.

Giuseppe

0 Karma

NK
Explorer

I enabled netstsat in $SPLUNK_HOME/etc/apps/Splunk_TA_nix/local/inputs.conf
I see Send_Q and Recv_Q (from "netstat -a"?) , but those look like the corresponding queue sizes in bytes.
I think the Windows/wmi equivalent reports traffic (bytes/sec) through the network adapter.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @NK ,

good for you, see next time!

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

Get Updates on the Splunk Community!

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Splunk Education Goes to Washington | Splunk GovSummit 2024

If you’re in the Washington, D.C. area, this is your opportunity to take your career and Splunk skills to the ...