Dashboards & Visualizations

How to convert bytes to gb in dashboard?

nedwards94
Engager

Created two panels with single value vizualisation on a dashboard displaying all traffic bytes inbound and outbound. Trying to convert the value to GB therefore need to divide it. Managed to get a search string that works on just a search, but doesn't display within the dashboard.

index="siem" sourcetype=proxy 
| stats sum(bytes_out) | eval GB_bytes=(bytes_out/1000000000) | stats count by GB_bytes
Tags (3)
0 Karma
1 Solution

renjith_nair
Legend

@nedwards94,

sum(bytes_out) gives the field as sum(bytes_out) itself. You need to alias it to bytes_out.

Try this

index="siem" sourcetype=proxy 
| stats sum(bytes_out)  as bytes_out| eval GB_bytes=(bytes_out/1000000000) | stats count by GB_bytes
---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

hunderliggur
Path Finder

KB = bytes/1024
MB = bytes/(1024*1024) = bytes/1,048,576
GB = bytes/(1024*1024*1024) = bytes/1,073,741,824

There is a ~7% difference in volume using the binary values versus the straight decimal value (decimal rate will appear "higher")

0 Karma

nedwards94
Engager

Ah, how annoying just a tiny addition. Thank you so much!

0 Karma

renjith_nair
Legend

@nedwards94,

sum(bytes_out) gives the field as sum(bytes_out) itself. You need to alias it to bytes_out.

Try this

index="siem" sourcetype=proxy 
| stats sum(bytes_out)  as bytes_out| eval GB_bytes=(bytes_out/1000000000) | stats count by GB_bytes
---
What goes around comes around. If it helps, hit it with Karma 🙂
Get Updates on the Splunk Community!

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...