I would like to know what is the command filter out repeat source port if I wanna analyse my log based on number of port being access per min.
Current command is: sourcetype="Lv30814" | stats count(Source_Port)
If you want to find the number of different ports seen in 1 minute spans - regardless of how many times each port occurs;
your base search | timechart span=1m dc(Source_Port)
/K
If you want to find the number of different ports seen in 1 minute spans - regardless of how many times each port occurs;
your base search | timechart span=1m dc(Source_Port)
/K
Thank You!