Ad slot: top

SPL

Traffic Volume by Forwarder

Description

Submitted by SplunkNinja

This Splunk search query will show you the top 10 "chattiest" forwarders on your network. I've used this query to determine why some forwarders were sending more data than others. The results are displayed in kilobits, you could use an eval to change it to the appropriate size for your network.
5 0
index="_internal" source="*metrics.lo*" group=tcpin_connections NOT eventType=* | eval sourceHost=if(isnull(hostname), sourceHost,hostname) | search sourceHost=*** | timechart per_second(kb) by sourceHost WHERE max in top5 useother=f

Comments

0 total

Be the first to comment on this SPL.

Leave a comment

You must log in to post a comment.

Ad slot: bottom