dhcp lease log events will capture the following fields only:
1. leasetime -> lease timestamp
2. leasedip -> leased ip address
3. userid -> user
4. session -> either "START or STOP"
Desired Output Table:
I have the search command below for a start. But i cannot figure out how do a time range search for each capture time in the csv file.
| search [|inputcsv test.csv | fields leasedip]
If i do "| fields leasedip capturetime", obviously it cannot match anything because capturetime is not equal to the leasetime
I'm currently looking at "gentimes" but I'm not sure if it is the correct command to use for this case or considering on switching to "inputlookup".
Any suggestions are very much appreciated. Thank You!
map like this:
| inputcsv test.csv | map search="search index=dhcp_leaselog leased_ip=$leased_ip$ | where lease_timestamp<$capture_time$ | dedup | eval capture_time=$capture_time$ | eval leased_ip=$leased_ip$ | fields userid, leased_ip, lease_time, capture_time"