Deployment Architecture

Bandwidth consumption - HF to IDX

splunk_kk
Path Finder

HI,

My architecture is UF>HF>IDX. There is a VPN tunnel between HF and IDX. Is there a way I can have the VPN bandwidth utilization via splunk?

1) This VPN is dedicated for HF to IDX communication (and the only link between HF and IDX). There is no other traffic passing through it.
2) I don't have any other mechanism to check the VPN utilization.
3) Can we get the details from Splunk internal logs to see how much mbps/kbps data in total was sent over the tunnel during a given timeperiod?

A search would really be helpful

Thanks!

Tags (1)
0 Karma

FrankVl
Ultra Champion

Look at the _internal index for the metrics.log from your indexers, specifically for group=tcpin_connections. And then filter that for connections from your HFs.
Alternatively: do the same for the metrics.log from your HFs and look at the tcpout_connections metrics.

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...