index=email
| transaction mid icid
| stats count(recipient) as receipent_count by sender
| where receipent_count>100
I am using this in a correlation search but it is returning only sender information in fields but I want src_ip ,dest_ip and src_user can some one help me in modifying the search
Like this:
index=email
| transaction mid icid
| stats count(recipient) as recipient_count BY sender src_ip dest_ip src_user
| where recipient_count>100
Like this:
index=email
| transaction mid icid
| stats count(recipient) as recipient_count BY sender src_ip dest_ip src_user
| where recipient_count>100
Hi @vikram1583 ,
Stats command filter out the fields include the required fields in the stats or you can try using eventstats
index=email
| transaction mid icid
| stats count(recipient) as receipent_count values(src_ip) values(dest_ip) values(user) by sender
| where receipent_count>100