Deployment Architecture

statics NICs with Splunk

Linh
Explorer

Hello, I'm a newbie with Splunk. I have a question.

How can I static and draw data from 4 NICs in one computer on Splunk?

 
 
 
 
 
 
 
 
 
 
 
Labels (2)
0 Karma

Linh
Explorer

Thanks for your reply, I will describe in detail my question.

I have 4 NICs on my computer and they are connected to 4 other computers. Each computer will sends " ping flood" to its of each NIC. Then, how can I collect number packets, bytes,... and draw them on my computer with Splunk

Linh_0-1602466888763.png

 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Linh .. on the system, there should be some logs which will have all the details about the ping flood on the NIC's. By using the Splunk Universal forwarder, you can monitor that logs and then once data reached splunk, you can run splunk search queries and understand the NIC's and their statistics. Let us know how it goes. thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

Linh
Explorer

Hi @inventsekar, thanks for your advise, I try to read RX packets on each NIC on ubuntu and save it on log file, then I do it work and draw it on Splunk currently. 

Linh_0-1602473940095.png

 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Nice.. so your issue got resolved or you have got something more, please suggest. if all good, please accept this as the solution. thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

Linh
Explorer

I have one more question. Can I ever clog or delay the chart by sending data from 4 computer? Something like: ping flood on each computer.

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Linh your question was bit confusing.. i assumed that you have UF with 4 NIC's, you want to get statistics about the NIC's.. if so, pls check this post:

https://community.splunk.com/t5/Deployment-Architecture/Multiple-NICs-Source-IP/m-p/36566

https://community.splunk.com/t5/Splunk-Enterprise-Security/Does-Splunk-support-double-NIC-interfaces...

 

 

(PS - i have given around 500+ karma points so far, received badge for that, if an answer helped you, a karma point would be nice!. we all should start "Learn, Give Back, Have Fun")

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...