arkime_spigraph
Display top values of a network field with a time-series graph to identify top talkers or detect value spikes over time.
Instructions
Top values of one Arkime field, with a time-series graph.
Good for finding top talkers or spotting a value that spikes over time.
Args: field: Arkime field, e.g. "ip.dst", "protocols", "http.host". expression: Optional Arkime filter to scope the data. size: Number of top values to return (1-100). time_from: Start time, epoch seconds. Omit = recent-only. time_to: End time, epoch seconds.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| size | No | ||
| field | Yes | ||
| time_to | No | ||
| time_from | No | ||
| expression | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |