I am trying to mimic the table below. I have the count of the source IP, but how do I get the count of the respective subnets? In the example, they have it in the cell of each subnet value. Here is what I have so far:
index=xxxx sourcetype=xxxx "xxxx"
| eval ERROR_CODE=case((RC="200"), "Success", (RC="400"), "User Not Found",(RC="401") , "Bad Password",(RC="500"), "Internal Server Error")
| rex field=_raw "TCIP='(?<subnet_24>\d+\.\d+\.\d+)\.\d+"
| rex field=_raw "TCIP='(?<subnet_16>\d+\.\d+)\.\d+\.\d+"
| eval subnet_24 = subnet_24 +".x"
| eval subnet_16 = subnet_16 +".x.x"
| stats count(TCIP) by subnet_24 subnet_16 TCIP
Any help is appreciated!
Hi
you should try eventstats instead of stats.
r. Ismo