Hi,
Can anyone tell me why this comment is not working? I have all the mentioned fields in my data, but when I add stats max(_time) as last_time by host,sourcetype,action,dest,dest_ip,dest_port,dev,index,msg,src,src_ip,src_port,vendor_action |dedup last_time,host,sourcetype,action,dest,dest_ip,dest_port,dev,index,msg,src,src_ip,src_port,vendor_action
I'm not getting any result. Here is my full search:
src=122.15.158.173 sourcetype=cisco:asa "Deny*" |stats max(_time) as last_time by host,sourcetype,action,dest,dest_ip,dest_port,dev,index,msg,src,src_ip,src_port,vendor_action |dedup last_time,host,sourcetype,action,dest,dest_ip,dest_port,dev,index,msg,src,src_ip,src_port,vendor_action
Two things:
Try this first to see if the are any events matching your requirements with data in all the required fields:
src=122.15.158.173 sourcetype=cisco:asa "Deny*"
host=*
sourcetype=*
action=*
dest=*
dest_ip=*
dest_port=*
dev=*
index=*
msg=*
src=*
src_ip=*
src_port=*
vendor_action=*
If that works then append the stats afterwards:
| stats max(_time) as last_time by host, sourcetype, action, dest, dest_ip, dest_port, dev, index, msg, src, src_ip, src_port, vendor_action
as i checked, "sourcetype=cisco:asa" events are not having a field "dev"
tried it without "dev" and its working fine..
src=122.15.158.173 sourcetype=cisco:asa "Deny*"|stats max(_time) as last_time by host,sourcetype,action,dest,dest_ip,dest_port,index,msg,src,src_ip,src_port,vendor_action |dedup last_time,host,sourcetype,action,dest,dest_ip,dest_port,index,msg,src,src_ip,src_port,vendor_action
No, it has Dev field.
oh ok. i thought cisco:asa logs may have same format. seems your environment is different. ok, thanks.
Two things:
Try this first to see if the are any events matching your requirements with data in all the required fields:
src=122.15.158.173 sourcetype=cisco:asa "Deny*"
host=*
sourcetype=*
action=*
dest=*
dest_ip=*
dest_port=*
dev=*
index=*
msg=*
src=*
src_ip=*
src_port=*
vendor_action=*
If that works then append the stats afterwards:
| stats max(_time) as last_time by host, sourcetype, action, dest, dest_ip, dest_port, dev, index, msg, src, src_ip, src_port, vendor_action