Hi.
I can see how much data goes into Graylog per day. If I have a sudden spike of input how do I identify which host is causing the spike? (Why is it called Outgoing traffic if that is the data I received into Graylog or am I misunderstanding?)
Can you not under Sidecars add a column with the total data the sidecar sent it over a period?
Unless there is a more obvious way I missed.
Hey @daniejstriata,
You could set up a dashboard with a table that shows a count of messages received by source over the past whatever time period.
It would look like this:
And set the visualization type to message table to get a list. We sort ours by message count descending.
Thank you! It works well!
This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.