i would like to get the total bandwidth used by a particular subnet in my network, please help, i am new in splunk,
we might need more details like how your field=values look like, and what's your sample search you started with.
hi prakash007, can you suggest a basic search that I can try out, totally new in this thing,
@ikaneng: how's your raw data look like, we need more details to come up with a search...
If it's a ipv4 you can have this in your base search, you might have to use cidrmatch for ipv6...
e.g: index=index_name sourcetype=stype subnet_ip=10.0.0.1/24 | stats count, max(connsbyHost) as max_bandwidth, min(connsbyHost) as min_bandwidth, avg(connsbyHost) as avg_bandwidth BY Interface
go though this splunk docs for reference..
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Aggregatefunctions#max.28X.29
http://docs.splunk.com/Documentation/Splunk/7.2.1/SearchReference/ConditionalFunctions#cidrmatch.28....