aws-vpc-flow((aws_account_id="*"), (region="**") )` | stats count as Packages by dest_ip | iplocation dest_ip | table dest_ip Country Region City Packages | sort -Packages
I want to display the dest_ip lookup host name in a separate column. Can anyone help?
Found answer
search 8 | lookup dnslookup clientip AS destip output clienthose as dest_resolved
Found answer
search 8 | lookup dnslookup clientip AS destip output clienthose as dest_resolved