Deployment Architecture

statics NICs with Splunk

Linh
Explorer

Hello, I'm a newbie with Splunk. I have a question.

How can I static and draw data from 4 NICs in one computer on Splunk?

 
 
 
 
 
 
 
 
 
 
 
Labels (2)
0 Karma

Linh
Explorer

Thanks for your reply, I will describe in detail my question.

I have 4 NICs on my computer and they are connected to 4 other computers. Each computer will sends " ping flood" to its of each NIC. Then, how can I collect number packets, bytes,... and draw them on my computer with Splunk

Linh_0-1602466888763.pngLinh_0-1602466888763.png

 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Linh .. on the system, there should be some logs which will have all the details about the ping flood on the NIC's. By using the Splunk Universal forwarder, you can monitor that logs and then once data reached splunk, you can run splunk search queries and understand the NIC's and their statistics. Let us know how it goes. thanks. 

Linh
Explorer

Hi @inventsekar, thanks for your advise, I try to read RX packets on each NIC on ubuntu and save it on log file, then I do it work and draw it on Splunk currently. 

Linh_0-1602473940095.pngLinh_0-1602473940095.png

 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Nice.. so your issue got resolved or you have got something more, please suggest. if all good, please accept this as the solution. thanks. 

Linh
Explorer

I have one more question. Can I ever clog or delay the chart by sending data from 4 computer? Something like: ping flood on each computer.

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Linh your question was bit confusing.. i assumed that you have UF with 4 NIC's, you want to get statistics about the NIC's.. if so, pls check this post:

https://community.splunk.com/t5/Deployment-Architecture/Multiple-NICs-Source-IP/m-p/36566

https://community.splunk.com/t5/Splunk-Enterprise-Security/Does-Splunk-support-double-NIC-interfaces...

 

 

(PS - i have given around 500+ karma points so far, received badge for that, if an answer helped you, a karma point would be nice!. we all should start "Learn, Give Back, Have Fun")

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...