Archive
Highlighted

Pivot search

New Member

hello ,
someone can help me to translate this pivot command in search command

| pivot proofpoint proofpointsearch count(proofpointsearch) AS "count(proofpointsearch)" SPLITROW sdomaine SPLITROW ipsender AS ip SPLITROW action AS action SORT 1000000 sdomaine ROWSUMMARY 0 COLSUMMARY 0 NUMCOLS 0 SHOWOTHER 1|table sdomaine ip action|search sdomaine!="NULL" sdomaine="$doamine$" ip!="NULL" ip="$ip$" action!="NULL" $status$|stats values(ip) as IPs values(action) as action count by sdomaine|rename s_domaine AS "Sender Domaine" |sort - count.

thank you in advance

Tags (1)
0 Karma
Highlighted

Re: Pivot search

Motivator

hey alliacom,

Try this,

.... | stats values(proofpoint) AS proofpoint values(proofpointsearch) AS proofpointsearch count(proofpointsearch) AS "count(proofpointsearch)" by sdomaine,ipsender,action | rename ipsender AS ip | table sdomaine ip action|search sdomaine!="NULL" sdomaine="$doamine$" ip!="NULL" ip="$ip$" action!="NULL" $status$|stats values(ip) as IPs values(action) as action count by sdomaine|rename sdomaine AS "Sender Domaine" |sort - count.

0 Karma
Highlighted

Re: Pivot search

Champion

Hi,

You can try :

    ..| stats count(proofpoint_search) AS "count(proofpoint_search)" by s_domain, ip_sender,action | sort s_domain | rename ip_sender AS ip | 
    table s_domain ip action|search s_domain!="NULL" s_domain="$doamin$" ip!="NULL" ip="$ip$" action!="NULL" $status$|stats values(ip) as IPs values(action) as action count by s_domain|rename s_domain AS "Sender Domain" |sort - count.
0 Karma