Splunk Search

Converting bytes to GB or MB

pmac22
Path Finder

Hey all, I was getting confused by some of the splunk answers for converting and couldn't figure out the eval portion of my query. Can someone shed some light on how I can convert the bytes_out field from my palo logs to MB and GB? Query below, thank you in advance!

index=pan_logs sourcetype=pan:traffic
| stats sum(bytes_out) AS bytes_out by user src_ip dest_ip
| where bytes_out>35000000
| sort - bytes_out

Tags (1)
0 Karma
1 Solution

ddrillic
Ultra Champion

In the spirit of - | eval GB=kb/1024/1024

View solution in original post

pmac22
Path Finder

Thanks guys. Worked like a charm! Here's my updated search...

index=pan_logs sourcetype=pan:traffic
| stats sum(bytes_out) AS bytes_out by user src_ip dest_ip
| where bytes_out>35000000
| eval MB_out=round(bytes_out/1024/1024,2)
| sort - MB_out

0 Karma

ddrillic
Ultra Champion

In the spirit of - | eval GB=kb/1024/1024

dmarling
Builder

@ddrillic You may want to convert your comment to an answer as it was basically the answer he needed. I just added a comment to make it more specific to his use case.

If this comment/answer was helpful, please up vote it. Thank you.
0 Karma

ddrillic
Ultra Champion

Sure thing @dmarling ; -)

0 Karma

dmarling
Builder

@ddrillic has it correct. bytes_out/1024 will get you kilobytes divide that by 1024 to get megabytes and divide that by 1024 to get gigabytes: | eval GB_out=bytes_out/1024/1024/1024 to get megabytes: | eval MB_out=bytes_out/1024/1024

If this comment/answer was helpful, please up vote it. Thank you.

pmac22
Path Finder

That worked out great! Thanks guys!

Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...