Hi, I am trying to build a dashboard to show a mapping between source IP and destination IP based on different connections (open or close). I was able to get the result like this but not sure how to present it in a visualization tool and group by the source IP. Any help would be appreciated.
Source IP, Destination IP, Connection Type, Count
10.2.12.3, 168.192.0.1, open, 24
10.2.12.3, 168.192.0.5, open, 45
10.2.12.6, 168.192.0.1, close, 12
10.2.12.4, 168.192.0.6, open, 4
Thanks
Thanks,
Jun
A Sankey diagram may be the solution. See https://splunkbase.splunk.com/app/3112
A Sankey diagram may be the solution. See https://splunkbase.splunk.com/app/3112
Thanks, @richgalloway It worked.