I just want to clean up my search of 'noise'as my stats table gets populated by duplicate values from the save latitude and longitude values.
index=newfortinet user=AARIBEB msg="URL belongs to a denied category in policy" direction=outgoing action=blocked
|stats sum(count) by dstip
|sort - count
|iplocation dstip
|where Country="Namibia"
|geostats count by Country globallimit=0
|fields - geobin
See attached result screanshot
Just add this:
... | dedup Namibia latitude longitude
index=newfortinet user=AARIBEB msg="URL belongs to a denied category in policy" direction=outgoing action=blocked
|stats sum(count) by dstip
|sort - count
|iplocation dstip
|where Country="Namibia"
|geostats count by Country globallimit=0
|fields - geobin
|eval tmp=Namibia."_".latitude."_".longitude
|dedup tmp
|fields Namibia, latitude, longitude
Hi, @schalkrust
How about it?