Clarification on transferred flows

Update: Although this thread has been closed with no response, my issue below has been resolved by adding a filter "final: true". The data transfer numbers in bytes are no longer backward-cumulative and now make sense with that filter. Thanks.


I'm trying to understand the following metric table that came with Packetbeat.

But, considering our WAN link throughput (1Gbps = 125MB/s --> ~70MB/s after overhead), each of these numbers seems way too big.

(e.g., 1st number in the last 15m in the below, which is 35GB for 15m for traffic between an inside host and an outside host)

I even doubt that the unit (Numeral.js format lower-case "b" in the 2nd screenshot) of these numbers is in bytes.

Below shows screenshots for the last 15m, 30m, 1h, 4h, 12h, and 24h.

image

image

image

image

image

image

Any comments would be much appreciated.

Thank you in advance!

  • Young

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.