Hi Splunkers, newish user here...
I'm looking at firewall logs, I want to create a table with number of blocked IP for each day, a cumulative daily average, number of daily block events, average events.
I thought this (which works with a single pair of stats/streamstats lines) would work:
index=phase1 action=block tag=site1
| stats dc(src) as dailyip by date_mday
| streamstats avg(dailyip) as ip_average
| stats count as dailyevt by date_mday
| streamstats avg(dailyevt) as evt_average
| table date_mday, ip_average, dailyip, dailyevt, evt_average
and create a table like this....
date_mday ip_average dailyip dailyevt evt_average
4 3082 3082
5 3439 3260.5
6 3578 3366.33
7 4210 3577.25
8 2545 3370.8
But it doesnt work.... It looks like I cannot use date_mday across 2 strings like that?
Can someone give me some hints (or a solution!!)?
Many thanks.
... View more