Getting Data In

Cisco Firewall Total bytes by ip address last 24 hours

rpetrini
Engager

How do you build a search to total the bytes transfered (sending and recieving) by ip address for the last 24 hours, by indexing a cisco firewall?

Tags (4)
0 Karma

sdaniels
Splunk Employee
Splunk Employee

Have you thought about getting this data via netflow and using the Netflow app on Splunkbase? It will give the details you are looking for I think.

http://splunk-base.splunk.com/apps/22328/splunk-for-netflow

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Gotcha, the Netflow app won't work on windows. The Splunk App for Cisco firewall will have the field extractions you are looking for and may already have a view for amount of traffic based on IP. I think it is fine on windows from what I recall.

0 Karma

rpetrini
Engager

Running on a windows server. Can I use the data from the cisco firewall?

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...