Hi,
is there a way to check which host is sending me the most traffic ? today my license had jammed.
Regards,
Shlomy.
You may try below search
index=* sourcetype=* NOT sourcetype=btool* NOT sourcetype=splunk* | eval esize=len(_raw) | stats count AS Example_Count, sum(esize) AS bytes BY host | eval GB=round(bytes/1024/1024/1024, 0)
You may try below search
index=* sourcetype=* NOT sourcetype=btool* NOT sourcetype=splunk* | eval esize=len(_raw) | stats count AS Example_Count, sum(esize) AS bytes BY host | eval GB=round(bytes/1024/1024/1024, 0)
thanks for your help ! very helpful !
(sorry for the late response)