Hi,
I'm trying to create a query for extract the SourceIP for traffic that exceed 1Gbps in 10minutes..
I create this SWQL query but the result is empty...
SELECT SourceIP
FROM Orion.Netflow.Flows
WHERE
(TimeStamp >= AddMinute(-11, DateTrunc('minute', GetUtcDate())) AND TimeStamp <= AddMinute(-2, DateTrunc('minute', GetUtcDate())))
AND NodeID IN (222)
GROUP BY SourceIP
HAVING ((SUM(EgressBytes)*8) / (10*60)) > 10000000
But If I search for NodeID or for Port, I find a one row result..
Maybe is because the result is multi-lines? I don't know.
Any suggestions?
Thanks