I have this string and want to add second value " accountNumber" to the chart. How I can do that?
Current string:
| rex "(?i) IP (?P[^ ]+)"
| rex "(?i) username (?P[^ ]+)"
| chart dc(UsrName) over clientIp
|sort - dc(UsrName)
I want add "account number" on the chart. I tried this, but didn't work.
| rex "(?i) IP (?P[^ ]+)"
| rex "(?i) username (?P<UsrName>[^ ]+)"
| chart dc(UsrName) over clientIp, accountNumber
| sort - dc(UsrName)
So, what I am trying to have a chart with accountNumber and client IP username.
thanks
Try something like this
| rex "(?i) IP (?P[^ ]+)"
| rex "(?i) username (?P<UsrName>[^ ]+)" | eval clientIp=clientIp+"-"+accountNumber
| chart dc(UsrName) over clientIp
| sort - dc(UsrName)
OR
| rex "(?i) IP (?P[^ ]+)"
| rex "(?i) username (?P<UsrName>[^ ]+)"
| stats dc(UsrName) over clientIp, accountNumber
| sort - dc(UsrName)