Splunk Search

Query to show inbound and outboud network traffic

israbenbr
Explorer

Hello everyone,

I am trying to create queries to show the max and average values of inbound and outbound network traffic (unit : Gbps) of my forwarders

I already configured the Splunk add on for unix and linux on my forwarders, but don't know which script to enable to collect the data needed

Also, i installed the Pavo network traffic app for splunk, but don't know how to configure it

For info, my splunk server is on a single instance deployment

Any ideas ? 

 

Thanks ! 

Labels (4)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

My previous response was mistaken.  To get network bandwidth, you want to enable bandwidth.sh.  It gives two fields of your interest, rxKB_PS and txKB_PS.  You need to convert them into GB per second at search time.

For questions about setting up input, the forum Getting Data In may give faster response.

0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...