Been poking around and trying to figure out how to pull up how much data has been sent from a specific host.
For example host 123 is sending CPU data every 10sec, how much data is that over the course of time = "X"
This should do it - this shows how much data has been indexed from various hosts
index=_internal source=*metrics.log group="tcpin_connections"
| eval sourceHost=if(isnull(hostname), sourceHost,hostname)
| stats sum(kb) as KB by sourceHost | eval KB = round(KB)
View solution in original post