I am just wondering how the Firewall Analyser calculates the amount of data sent to/from a host based on the syslog messages.
I am seeing a lot of traffic transferred between 2 servers and I would like to know how Firewall Analyser gets this information.
Thanks,
JP