I have the following search in which I am looking for a list of each source IP, the list of websites they hit, the count of GETs per website, and then an overall total of GETs for all websites
index=foo http_method=GET
| bucket _time span=5m
| stats count by src, website
| sort -count
| where count >= 5
| stats list(website) as Website, list(count) as count, sum(count) as Total by src
| sort -Total
How can I modify the search to query for only IPs that have hit more than 5 websites within the 5-minute time span?
Thx
Give this a try
index=foo http_method=GET
| bucket _time span=5m
| stats count by src, website
| sort -count
| where count >= 5 | evenstats dc(website) as sites by src | where sites>=5
| stats list(website) as Website, list(count) as count, sum(count) as Total by src
| sort -Total
Give this a try
index=foo http_method=GET
| bucket _time span=5m
| stats count by src, website
| sort -count
| where count >= 5 | evenstats dc(website) as sites by src | where sites>=5
| stats list(website) as Website, list(count) as count, sum(count) as Total by src
| sort -Total
Aweomse - worked perfectly!
Thx