Hi,
My requirement is to find is same pair of source and ip addresses are being used.
for example if this is my table
src_ip ,dest_ip,action
192.168.10.2,192.168.10.3,block
192.168.10.21,192.168.10.13,block
192.168.10.2,192.168.10.3,allow
i want as a result:
192.168.10.2,192.168.10.3,allow
192.168.10.2,192.168.10.3,block
How to achieve this?
Thanks
Hi,
you can use the dedup command:
... | dedup src_ip dest_ip action
or you can use stats:
... | stats count by src_ip dest_ip action | fields -count
If possible, you should use stats, it should be faster than dedup. But without further ado, after a stats you only have the fields left, that you used in your by clause.
Greetings
Tom
you may try this:
... | eventstats count by src_ip ,dest_ip | where count = 2
Hi,
you can use the dedup command:
... | dedup src_ip dest_ip action
or you can use stats:
... | stats count by src_ip dest_ip action | fields -count
If possible, you should use stats, it should be faster than dedup. But without further ado, after a stats you only have the fields left, that you used in your by clause.
Greetings
Tom