I'm trying to find and filter out large talkers through the packet decoder that could help in reducing our license usage.
What's the best way to find these large talkers on the decoder?
You could do something like a top 10 source addresses sorted by size
Aggregate by ‘packet size’
Where ip.sec exists (You could put a network zone label in here too)
And choose 10 (or what ever count you want)
That seems simple enough, I'll give it a try, thanks Dave.
When you say 'aggregate by 'packet size'', is that the 'Summarize' field in the rule builder? If so, would 'packet count' be the correct one to select?
I don't see aggregate or packet size in the rule builder. Running 22.214.171.124
Summarize by ‘session size’
That’s what you want.
Thanks Dave, what you suggested was exactly what I was looking for.
Retrieving data ...