Knowledge Management

is there a way to group eventtypes

ruisantos
Path Finder

I would like a list of all eventtypes associated to an IP on a single table. Is there a way to perform this?

I would like to have a list like.

ip=1.1.1.1 eventtype=google,maps,yahoo,amazon

Tags (1)
0 Karma
1 Solution

ziegfried
Influencer
10.1.1.1 | typer | fields eventtype | mvexpand eventtype | dedup eventtype | table eventtype

View solution in original post

0 Karma

ziegfried
Influencer
10.1.1.1 | typer | fields eventtype | mvexpand eventtype | dedup eventtype | table eventtype
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...