Splunk Search

How to search the sum of bytes by IP?

arkonner
Path Finder

I am trying to find the total bytes usage by user/ip - I have in the index the various clientip and the bytes usage on a specific moment.
The result of my search would report for each user/ip the total bytes based on the various preset time

Tags (3)
0 Karma

alemarzu
Motivator

Hi there, try with this

main search | stats sum(bytes_field) by User IP
0 Karma
Get Updates on the Splunk Community!

Index This | What did the zero say to the eight?

June 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

Splunk Observability Cloud's AI Assistant in Action Series: Onboarding New Hires & ...

This is the fifth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Now Playing: Splunk Education Summer Learning Premieres

It’s premiere season, and Splunk Education is rolling out new releases you won’t want to miss. Whether you’re ...