我正在尝试获取 SWQL 中的查询以获取前 15 个对话,包括 Ingress 和 Egress。
下面是我写的查询,但数据似乎不匹配。
SELECT TOP 15 Timestamp,SourceIP as A_IP, SourceHostname as A_Hostname, DestinationIP as B_IP, DestinationHostname as B_Hostname
, ROUND(SUM(Bytes) / (1024 * 1024),2) As BytesMB
, ROUND(SUM(IngressBytes) / (1024 * 1024),2) as IngressBytes
, ROUND(SUM(EgressBytes) / (1024 * 1024),2) as EgressBytes
, SUM(IngressPackets) as IngressPackets
, SUM(EgressPackets) as EgressPackets
, SUM(Packets) as Packets
FROM Orion.Netflow.FlowsByConversation
WHERE Timestamp >= ADDHOUR(-2, GETDATE()) AND InterfaceIDRx='xxxxx'
GROUP BY SourceIP, DestinationIP, SourceHostname, DestinationHostname, Timestamp
ORDER BY BytesMB DESC
请如果有人可以帮助我得到这个。