as part of investigation i want to filter the large outbound traffic (1GB data in 1hr) from the  source ip's based on request.

Question asked by srikanth jonnalagadda on Sep 24, 2019

i have verified the logs messages, it is calculating the payload of request and response in meta key "large out bound data transfer". is there any other way to filter the only request base filter for the source ip list or any other suggestions. need help on this.