# GB/m transferred over time between hosts (internal & external)

**URL:** <https://discuss.elastic.co/t/gb-m-transferred-over-time-between-hosts-internal-external/110434>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [December 5, 2017, 11:16pm UTC](https://discuss.elastic.co/t/gb-m-transferred-over-time-between-hosts-internal-external/110434 "2017-12-05T23:16:12Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![learner](https://avatars.discourse-cdn.com/v4/letter/l/b782af/32.png) [@learner](https://discuss.elastic.co/u/learner)\
**Post date:** [December 5, 2017, 11:16pm UTC](https://discuss.elastic.co/t/gb-m-transferred-over-time-between-hosts-internal-external/110434/1 "2017-12-05T23:16:12Z")

</div>

I tried using Packetbeat to make a dashboard to show how much GB/m or TB/h transferred between various hosts in LAN and other hosts in and out, whether between internal hosts or between internal and external hosts.

When I use **source.stats.net\_bytes\_total** and **dest.stats.net\_bytes\_total** as **sum metrics** , I cannot convince myself about the cumulative TB/h that came up, as our WAN bandwidth has no way to be able to transfer the number of TB/h that the dashboard shows.

What would be the fields to use to show MB/GB/TB transferred per minute and hours?

Or, am I doing wrong to capture what I want to get using the wrong aggregation type (sum), maybe?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/7/970ce0e7ec216c77cfeeb7558faeab1e6ef5ce8b.png)

Thank you for your help in advance!

- Young

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [December 5, 2017, 11:29pm UTC](https://discuss.elastic.co/t/gb-m-transferred-over-time-between-hosts-internal-external/110434/2 "2017-12-05T23:29:06Z")

</div>

Are you filtering on `final:true`?

> If you want to aggregate sums of traffic, you need to filter on final:true, or use some other technique, so that you get only the latest update from each flow. You can disable intermediate reports by setting period: -1s.

Source: [Configure flows to monitor network traffic | Packetbeat Reference [8.11] | Elastic](https://www.elastic.co/guide/en/beats/packetbeat/current/configuration-flows.html)

---

<div class="post-metadata">

**Author:** ![learner](https://avatars.discourse-cdn.com/v4/letter/l/b782af/32.png) [@learner](https://discuss.elastic.co/u/learner)\
**Post date:** [December 5, 2017, 11:56pm UTC](https://discuss.elastic.co/t/gb-m-transferred-over-time-between-hosts-internal-external/110434/3 "2017-12-05T23:56:24Z")

</div>

Hi Andrew,

That's it. I'm now convinced with the bytes transferred after adding that filter to use final:true.

So, just to confirm, if final:false, I guess it's cumulative from the very beginning of the time when the Packetbeat started collecting the packets and if final:true, only for the time duration specified (e.g., last 4 hours, last 12 hours, etc.)?

Thank you very much!

- Young

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [December 6, 2017, 12:12am UTC](https://discuss.elastic.co/t/gb-m-transferred-over-time-between-hosts-internal-external/110434/4 "2017-12-06T00:12:10Z")

</div>

If you do not filter out events where `final: false` then you are summing up the amount of bytes contained in each flow update. And the number of bytes contained in each update is a summation since the flow started. For example:

Flow Event 1: {final: false, bytes: 10}  
Flow Event 2: {final: false, bytes: 20}  
Flow Event 3: {final: true, bytes: 40}

If you fail to filter out the flow updates you will see 70 bytes which is wrong because the total amount is 40 bytes.

---

<div class="post-metadata">

**Author:** ![learner](https://avatars.discourse-cdn.com/v4/letter/l/b782af/32.png) [@learner](https://discuss.elastic.co/u/learner)\
**Post date:** [December 6, 2017, 12:30am UTC](https://discuss.elastic.co/t/gb-m-transferred-over-time-between-hosts-internal-external/110434/5 "2017-12-06T00:30:40Z")

</div>

Thank you again, Andrew!

- Young

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 3, 2018, 6:39pm UTC](https://discuss.elastic.co/t/gb-m-transferred-over-time-between-hosts-internal-external/110434/7 "2018-01-03T18:39:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
