Hey guys.
I need to know what ip have less events then avarage of all devices.
for example:
ip events
1.1.1.1 11
2.2.2.2 10
3.3.3.3 9
4.4.4.4 1
so average is 7.75 and i want to find ip 4.4.4.4
Eventstats is your friend. Assuming your fields are named IP and events:
| eventstats avg(events) as avg_events
| where events < avg_events
Eventstats is your friend. Assuming your fields are named IP and events:
| eventstats avg(events) as avg_events
| where events < avg_events