- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

I am looking to find events where IP address changes from previous to current, however using fist(ip) and last(ip) misses the events in between the first and last...
Ideally I am looking to find when a change occurs for the IP value and then look at the previous IP value... this comparison is then used to find ip geoloc and calc the speed = dist/time with haversine app.
Thank you
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Look at the streamstats
command for this. Any tracking of change over time, streamstats
is your go-to verb.
We'll assume there is a key called user
.
your search that gets the records you want, with at least these fields
| fields _time user someIP
| sort 0 _time
| streamstats current=f last(someIP) as priorIP last(_time) as priorTime by user
| where NOT (someIP=priorIP)
... the remainder of your search.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Look at the streamstats
command for this. Any tracking of change over time, streamstats
is your go-to verb.
We'll assume there is a key called user
.
your search that gets the records you want, with at least these fields
| fields _time user someIP
| sort 0 _time
| streamstats current=f last(someIP) as priorIP last(_time) as priorTime by user
| where NOT (someIP=priorIP)
... the remainder of your search.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Wow that is awesome!!! Thanks
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

You are quite welcome. streamstats
processes the records in order, remembering only the records it has already seen, so you must sort the records in the order you want before you apply the command.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

so that is the purpose of sort 0 > return all results, thanks
