All Apps and Add-ons

Squid Proxy bytes_in,bytes_out, and bytes- Can we use this app to determine the bandwidth for a given time?

eholz1
Contributor

Hello Splunk Experts,

I am using the Squid Proxy dashboard, and the TA squid plugin, etc. Works well.

I notice the dashboard uses the "sourcetype=squid" to gather data. On the splunk documentation for the proxy, the site suggests using the "squid:access;recommended" for the Squid Proxy TA  plugin.

I have modified the inputs.conf file on my forwarder to use index=squid, and sourcetype=sqid, but

I have the squid.conf file using the splunk recommended log format - everything works.

My question is could we use this app to determine the bandwidth for a given time frame?

I see values: bytes, bytes_in (mostly = 181 for many events), and bytes_out.

Can any of these values provide information on total bandwidth or usages?

thanks,

eholz1

 

Labels (1)
Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

By "bandwidth" I assume you want some sort of bytes per second measurement? So, yes, both bytes in and bytes out would be very useful in this context. However, you would also need a couple of time fields, e.g. at least two out of three of start time of transmission, end time of transmission and duration of transmission.

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

By "bandwidth" I assume you want some sort of bytes per second measurement? So, yes, both bytes in and bytes out would be very useful in this context. However, you would also need a couple of time fields, e.g. at least two out of three of start time of transmission, end time of transmission and duration of transmission.

eholz1
Contributor

Thanks for the reply, I see there is quite a lot of things that can be searched.

I also see time is a factor as well. I would like to be able to check, for a specific src_ip, assuming the

user is doing a download - to sum the process, bytes_in, I would guess, and TCP breaks the

total download into smaller pieces, etc. So I should be able to get the time of the download, and the total amount of bytes downloaded.  Does that make sense,

 

Thanks again,

eholz1

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...