Hi,
I have some sylog events, login failed and login success in particular. I can determine if the event is success or failed by a field (field1) which contain something like "success" or "failure". In the event I Have also a field mac_address(field2) which contain some MAC address. I need to count the number of mac address that exist in failure but nerver exist in success.
Can you help me???
Thanks in advance
Try something like this:
index=foo sourcetype=bar
| stats values(field1) as status by field2
| where mvcount(status)=1 and status="failure"
Try something like this:
index=foo sourcetype=bar
| stats values(field1) as status by field2
| where mvcount(status)=1 and status="failure"
Hi somesoni2,
thank you so much for your answer, I think it's working. So the result is the list of mac address that never had a login success, right? And if I want a count of this result, what I need to add to the query?
Thank you so much