Splunk Search

If I have a field containing the size of a single packet, how can I search the size of used network traffic by source IP?

tonifrommknecht
Engager

Hello,

I have to find out the used network traffic by source IPs.
I've got a field which contains the size of a single packet, but how can I find out the whole size of the used traffic?

Thanks in advance!

0 Karma
1 Solution

javiergn
Super Champion

Unless I am mistaking your question, I would simply use "stats sum(sizefield)" and then normalise that to MB or GB

View solution in original post

0 Karma

javiergn
Super Champion

Unless I am mistaking your question, I would simply use "stats sum(sizefield)" and then normalise that to MB or GB

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...