Can you do subsearches with tstats alone?
| tstats values(DM.app) AS App FROM datamodel=DM BY DM.source [|
tstats count FROM datamodel=DM WHERE DM.cat="foo" BY DM.dest |
rename DM.dest AS DM.source |
table DM.source ]
Source/dest are IPs - I want to get all the dest IPs of a certain server type (foo), then use those dest IPs as the source IPs for my main search.
The error that stops me is DM.source=1.2.3.4 (an IP address will show up here). I'm clearly missing something here and would appreciate any help.
Try like this
| tstats values(DM.app) AS App FROM datamodel=DM BY DM.source | search [|
tstats count FROM datamodel=DM WHERE DM.cat="foo" BY DM.dest |
rename DM.dest AS DM.source |
table DM.source ]
Try like this
| tstats values(DM.app) AS App FROM datamodel=DM BY DM.source | search [|
tstats count FROM datamodel=DM WHERE DM.cat="foo" BY DM.dest |
rename DM.dest AS DM.source |
table DM.source ]