Dashboards & Visualizations

How to convert bytes to gb in dashboard?

nedwards94
Engager

Created two panels with single value vizualisation on a dashboard displaying all traffic bytes inbound and outbound. Trying to convert the value to GB therefore need to divide it. Managed to get a search string that works on just a search, but doesn't display within the dashboard.

index="siem" sourcetype=proxy 
| stats sum(bytes_out) | eval GB_bytes=(bytes_out/1000000000) | stats count by GB_bytes
Tags (3)
0 Karma
1 Solution

renjith_nair
SplunkTrust
SplunkTrust

@nedwards94,

sum(bytes_out) gives the field as sum(bytes_out) itself. You need to alias it to bytes_out.

Try this

index="siem" sourcetype=proxy 
| stats sum(bytes_out)  as bytes_out| eval GB_bytes=(bytes_out/1000000000) | stats count by GB_bytes
Happy Splunking!

View solution in original post

hunderliggur
Path Finder

KB = bytes/1024
MB = bytes/(1024*1024) = bytes/1,048,576
GB = bytes/(1024*1024*1024) = bytes/1,073,741,824

There is a ~7% difference in volume using the binary values versus the straight decimal value (decimal rate will appear "higher")

0 Karma

nedwards94
Engager

Ah, how annoying just a tiny addition. Thank you so much!

0 Karma

renjith_nair
SplunkTrust
SplunkTrust

@nedwards94,

sum(bytes_out) gives the field as sum(bytes_out) itself. You need to alias it to bytes_out.

Try this

index="siem" sourcetype=proxy 
| stats sum(bytes_out)  as bytes_out| eval GB_bytes=(bytes_out/1000000000) | stats count by GB_bytes
Happy Splunking!
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...