I want to make a table or a graph that shows top hosts / IPs uploading a large amount of data transfer to the outside domains.
Probably I want a table/metric that shows:
Source IP addresses (of internal hosts initiating outbound data transfer)
Destination IP addresses (of external hosts over WAN in outside domains)
Is this possible?
I looked up various sample visualizations that came with Packetbeat and couple of them seem close to what I'm trying to do but the numbers of the transfer amount didn't make sense to me.
Could someone please give me a good direction?
Thank you very much in advance!