Hi all
Trying to work on something which currently shows a bunch of IP hits and counts against it, the current output is the last 2 hours
Query:
index=source sourcetype="source"
| stats count values(Hostname) by SourceIP
| sort by -count
| rename "count" to "Total count", "values(Hostname)" to "Hosts"
Output:
IP Count
100.100.100.100 5
I want to add a new column called "Last30days" that looks at the IP address found in column 1 and a count search for the last 30 days, so like above but another column for the last 30days, final output below.
IP Count Last30days
100.100.100.100 1 10
tried various variaitions but can't get it to work
Hi @anlePRH ,
you could try something like this (to adapt to your requirement):
index=source sourcetype="source"
| eval type=if(_time>now()-86400,"Today","Last30days")
| chart count OVER SourceIP BY type
Ciao.
Giuseppe