Splunk Search

how to show top talker information based on the CSV file received from analyzer

tailesley
New Member

HI,

Im very new to Splunk, i still learning to get splunk work to provide a high level report to the management to review. I have the data extracted from a csv file below. I would like to show the top talkers based on the IP address given below by adding both the byte_sent and byte_receive. How can i do this?

22/08/2011 21:38:59,IP-64.236.16.139,2263,7
22/08/2011 21:38:59,IP-64.128.203.22,115748,86

2263 is the byte_sent while 7 is the byte_received.
115748 is the byte_sent while 86 is the byte_received.

Tags (3)
0 Karma

mzorzi
Splunk Employee
Splunk Employee

There are few ways to do this:

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...