Hi,
I have a search result that shows IP addresses that query a DNS server but how do I filter the search result to only show a particular host IP address.
The search so far just returns all results:
index="DNS-misc" sourcetype="named-query"
Thanks,
Assuming the events contain the IP you're looking for and you want to show events containing 1.2.3.4 only you can do this:
index="DNS-misc" sourcetype="named-query" 1.2.3.4
If the filtered IP is extracted to a field, for example "host", you can do this:
index="DNS-misc" sourcetype="named-query" host=1.2.3.4