I Want the timelion bandwitch, but the number of bytes is by connection not by second.
Ex: The connection beetween 192.168.0.1:80 and 192.168.0.1:54220 have begin at 10:00 am and end at 10:05 am. The total of bytes communication is 250 bytes.
Thanks for you reply, I have found a bypass solution.
It's not optimized but that works.
I use the plugin logstash-filter-ruby on logstash for build 2 news fields:
1 field with the bandwitch by second and an other with all date on the rang.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.