How do I check which major destinations generate the most logs on a specific firewall host = 10.22.44.254? I would like to know the correct command to know the main destinations and also how to filter without them, to know how much license I would save if I don't receive them?
@renangomes - You can use the below search:
index=<firewall index> host="10.22.44.254"
| top 10 dest
You can see the percentage and see your current license usage by this host and see X percentage of that license usage you will save.
(You can check the license usage by this host on Monitoring Consoles' Historic License Usage page.)
I hope this helps!!!