Hi,
I tried your dataset and it' s working. I just changed the IP addresses you use. What do you mean about " stuff dose not work as i expect it to. " ?
What is the output? What should be the output?
I recommend to write the fields between these characters: `` (ASCII code ALT+96).
Something like:
SELECT `dstip`, SUM(`sentbyte`+`rcvdbyte`) AS volume
FROM $log
WHERE `status`=' accept'
AND `srcintf`=' port1'
AND (`dstip` LIKE ' 8.8.8.%' OR `dstip` LIKE ' 193.86.13.%' )
GROUP BY `dstip`
HAVING SUM(`sentbyte`+`rcvdbyte`)>0
ORDER BY `dstip`
I' m running on version 5.0.2 so the filed names are a little bit different like V5 `dstip` is V4.3 `dst` etc. Differences between V5 and V4 can be found on the first page in the PDF document: http://docs.fortinet.com/fgt50.html - section Log Message Reference
I see you are using sum(sent+rcvd)/1048576 - where you receive traffic in MB. If you will add this output in chart you don' t have to do it. You can leave only the sum(sent+rcvd) the chart will recalculate it into kB, MB and GB.
Regards,