Splunk Search

Bandwidth Report

rhelie
Engager

Hello,

I am new to Splunk and I set it up and configured my Sonicwall TZ200 to send syslog information to it. That works fine I have data going into splunk but I would like to run a report on total bandwidth usage for that unit based on a period of time.

I tried running a search but there is no "usage" field (as described in the video). Did I do something wrong? Is it a model specific problem? Is there a work around?

Thanks

Robert

Tags (2)

lukejadamec
Super Champion

I think you need to be searching for bytesRx for bytes received, bytesTx for bytes transmitted, rcvd for bytes received within a connection, and sent for bytes sent within a connection from the syslog.

0 Karma

rhelie
Engager

I do not seem to have an option for bytes Received or Sent. I see RCVD and Sent but that does not seem to be bytes.

0 Karma
Get Updates on the Splunk Community!

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...