Customer is asking for two daily report (covering 24 hour window) for the following:(bluecoat)
Search being used:
Sourcetype=bcoat_proxysg “key value pair that indicates filesharing activity”|table _time “bluecoat host IP by field extraction name” “status code” “URL_String field extraction” “Categories Field Extraction”
Any suggestions/recommendations would be appreciated.
Thanks,
Bill
Hello
I think you are looking for this:
earliest=-1d@d+1h latest=-1d@d+2h
try like :
Sourcetype=bcoat_proxysg “key value pair that indicates filesharing activity” earliest=-24h latest=now|table _time “bluecoat host IP by field extraction name” “status code” “URL_String field extraction” “Categories Field Extraction”
According to bluecoat's reference, the category name is: "Peer-to-Peer (P2P)". Or from the url, catnum=83?
https://sitereview.bluecoat.com/catdesc.jsp?catnum=83
Here's the full list of categories: https://sitereview.bluecoat.com/categories.jsp