When I run the following search, I get a list of countries and their count.
eventtype=cisco-firewall src_ip="*" dest_port="445" | iplocation src_ip | stats count by Country
But when I click on one of the countries and click "View Events" it runs the new search below but returns "No results found" even though I know the Country has events from the first search based on the count. What am I doing wrong?
eventtype=cisco-firewall src_ip="*" dest_port="445" Country=Canada| iplocation src_ip
eventtype=cisco-firewall src_ip="*" dest_port="445" | iplocation src_ip | search Country=Canada
eventtype=cisco-firewall src_ip="*" dest_port="445" | iplocation src_ip | search Country=Canada
Isn't the field Country
only available after the iplocation
command?
I think there is a bug in the Cisco Firewall app for "View Events"
Changing the search to this works as you suggested:
eventtype=cisco-firewall src_ip="*" dest_port="445" | iplocation src_ip | search Country=Canada