My environment is not as full as these, I have atm 3 variables
subject=ID of the user
IP=IP address from where they have logged on
from IP I can obtain the fields "lat" and "lon"
Then with some simple string magic I am looking at the following
index=main eventtype="loginevents" subject=* | fields ip subject _time | iplocation ip | eval lat=tostring(lat), lon=tostring(lon) | eval latlon=lat.", ".lon | stats count by ip latlon
My issue is that this results just give me basic statistic data, what i want is to compare the 2 last logins and see how far those 2 locations are, so it would be adding the previous login's lat and lon in different fields, any idea to apply this?