Security

How do I find the bandwidth usage per user in my firewall logs?

Explorer

i want to know the bandwidth usage per user in my firewall logs. Can you tell me how to search my firewall logs:

 devname="fg"  type="traffic" subtype="forward" level="notice"   srcname="NP"  dstport=161  dstintfrole="lan"  proto=17 action="accept" user="user X" authserver="FSSO" policytype="policy" service="SNMP" dstcountry="Reserved" " duration=960 sentbyte=78270 rcvdbyte=120261 sentpkt=622 rcvdpkt=621 appcat="unscanned" sentdelta=6755 rcvddelta=10247osname="Windows 8.1 / 2012 " 
0 Karma
1 Solution

SplunkTrust
SplunkTrust

@khanlarloo,
Try this and verify with your tests

index="your index" source="your firewall source" | stats sum(rcvdbyte) as rcvd,sum(sentbyte) as sent by user
|eval bandwidth=rcvd + sent

View solution in original post

0 Karma

SplunkTrust
SplunkTrust

@khanlarloo,
Try this and verify with your tests

index="your index" source="your firewall source" | stats sum(rcvdbyte) as rcvd,sum(sentbyte) as sent by user
|eval bandwidth=rcvd + sent

View solution in original post

0 Karma

Explorer

thank you.

0 Karma

Explorer

Thank you.

0 Karma