Greetings, I'm trying to create a report that only shows 3 things in a search. I need to be able to not show everything else.
This is my search:
host=192.168.64.18 Group=* Username=* IP=* NOT "Session disconnected" NOT "Connection terminated for peer*"
I would prefer not having to do huge number of NOT statements to remove that extra fields.
yes plus the host. The idea for this report is for another group to run it and see who is connected via VPN
Some search terms...| table host Group Username IP
Some search terms means:
index=<your index name> earliest=<time that you need> latest=<time that you need>
and other search terms as per your need