Just trying to find way to get src or dst info for matching signature group by values
| tstats allow_old_summaries=true count from datamodel=Intrusion_Detection by IDS_Attacks.signature | `drop_dm_object_name("IDS_Attacks")` | search [|inputlookup org_applicationattack.csv| fields signature ] | xswhere count from count_by_signature_1h in ids_attacks by signature is above minimal | where count >50 | fields signature count source ids_type vendor action
The Intrusion_Detection datamodel has both src and dest fields, but your query discards them both.
Verify the src and dest fields have usable data by debugging the query. Start by stripping it down.
| tstats allow_old_summaries=true count from datamodel=Intrusion_Detection by IDS_Attacks.signature
| `drop_dm_object_name("IDS_Attacks")`
If you have usable data at this point, add another command.
| tstats allow_old_summaries=true count from datamodel=Intrusion_Detection by IDS_Attacks.signature
| `drop_dm_object_name("IDS_Attacks")`
| search [|inputlookup org_applicationattack.csv| fields signature ]
Continue this process until the data you needs goes away and you'll have found the cause.