I need to write a search to detect the long duration of data transfer between a src and dest. can some one help me on the same.
| tstats range(_time) as duration where index=your_index by src dest
| where duration > your_threshold
If the above doesn't work:
index=your_index
| stats range(_time) as duration by src dest
| where duration > your_threshold
| tstats range(_time) as duration where index=your_index by src dest
| where duration > your_threshold
If the above doesn't work:
index=your_index
| stats range(_time) as duration by src dest
| where duration > your_threshold