Splunk Search

Query to show inbound and outboud network traffic

israbenbr
Explorer

Hello everyone,

I am trying to create queries to show the max and average values of inbound and outbound network traffic (unit : Gbps) of my forwarders

I already configured the Splunk add on for unix and linux on my forwarders, but don't know which script to enable to collect the data needed

Also, i installed the Pavo network traffic app for splunk, but don't know how to configure it

For info, my splunk server is on a single instance deployment

Any ideas ? 

 

Thanks ! 

Labels (4)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

My previous response was mistaken.  To get network bandwidth, you want to enable bandwidth.sh.  It gives two fields of your interest, rxKB_PS and txKB_PS.  You need to convert them into GB per second at search time.

For questions about setting up input, the forum Getting Data In may give faster response.

0 Karma
Get Updates on the Splunk Community!

Changes to Splunk Instructor-Led Training Completion Criteria

We’re excited to share an update to our instructor-led training program that enhances the learning experience ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

❄️ Welcome the new year with our January lineup of Community Office Hours, Tech Talks, and Webinars! 🎉 ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...