Hi to everyone
I have this search:
sourcetype="cisco:asa" | stats count by src_ip,dest_ip | sort -count | stats list(dest_ip),list(count) by src_ip
With this output:
I need to add a column with the total count by src_ip (sum of all the count for each list(count) value)
Does someone knows how to do this?
regards
Try something like this
sourcetype="cisco:asa" | stats count by src_ip,dest_ip | sort -count | eventstats sum(count) as Total by src_ip | stats list(dest_ip),list(count) values(Total) as Total by src_ip
Try something like this
sourcetype="cisco:asa" | stats count by src_ip,dest_ip | sort -count | eventstats sum(count) as Total by src_ip | stats list(dest_ip),list(count) values(Total) as Total by src_ip
Very well, it's working, thanks you very much!