Reporting

Add values together for report

Dragonnet
New Member

I have a SYSLOG output from a netscreen. There are two fields in each record that contain a value (sent) and (rcvd). I have enclosed an example below. I want to create a bar chart that will show the sum of these two values for the top ten IP addresses in (dst)

I have tried various syntaxes in the report command pipe * | timechart sum(sent) by dst

  • | timechart sum(sent+rcvd) by dst
  • | timechart sum((sent)+(rcvd)) by dst
  • | timechart sum((sum(sent)+(sum(rcvd)) by dst

But clearly I am missing something in the syntax

ssg5-serial: NetScreen device_id=0162102007000604 [Root]system-notification-00257(traffic): start_time="2010-10-26 11:34:30" duration=4 policy_id=6 service=icmp proto=1 src zone=Untrust dst zone=Trust action=Permit sent=78 rcvd=78 src=212.21.121.89 dst=212.21.101.193 icmp type=8 src-xlated ip=212.21.121.89 dst-xlated ip=212.21.101.193 session_id=2607 reason=Close - RESP\x00

Tags (2)
0 Karma

bwooden
Splunk Employee
Splunk Employee

One way...

 ... | timechart eval(sum(sent)+sum(rcvd)) by dst
Get Updates on the Splunk Community!

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...