2019-07-30 07:59 AM
Is there any way to check or calculate the total amount of logs being sent from a particular event source?
For instance, the metered license usage shows the total size of log data streaming into SA, from all event sources. Is there a way to check how much log data (GB / day) is a particular event source, say a domain controller sending?
2019-07-30 08:18 AM
Visham
You can run a report for 24 hours and get an idea of the total log size per device or per decoder
In the reporting engine create a rule with the following options:
Aggregation -> size
Select device.type or did or device.ip
Where medium=32
Run that for 24 hours and examine the results
Dave
2019-07-30 08:18 AM
Visham
You can run a report for 24 hours and get an idea of the total log size per device or per decoder
In the reporting engine create a rule with the following options:
Aggregation -> size
Select device.type or did or device.ip
Where medium=32
Run that for 24 hours and examine the results
Dave
2019-07-30 08:46 AM
Thanks Dave