Getting Data In

Cisco Firewall Total bytes by ip address last 24 hours

rpetrini
Engager

How do you build a search to total the bytes transfered (sending and recieving) by ip address for the last 24 hours, by indexing a cisco firewall?

Tags (4)
0 Karma

sdaniels
Splunk Employee
Splunk Employee

Have you thought about getting this data via netflow and using the Netflow app on Splunkbase? It will give the details you are looking for I think.

http://splunk-base.splunk.com/apps/22328/splunk-for-netflow

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Gotcha, the Netflow app won't work on windows. The Splunk App for Cisco firewall will have the field extractions you are looking for and may already have a view for amount of traffic based on IP. I think it is fine on windows from what I recall.

0 Karma

rpetrini
Engager

Running on a windows server. Can I use the data from the cisco firewall?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...