i have a Firewall Log and want to count the sending/receiving domains.
My problem is that there is for one email three or more log entrys.
Each message has a uniqe ID, which is available in every associated log entry.
Is it possible to merge these, so that i dont count an email twice or more.
Thank you 🙂
My current search looks like this:
| rex field=_raw "to=<(?[\w\d\.\-]+\@(?[\d\w\.\-]+)\>)"
| stats count(domain2) AS Anzahl by domain2
| rename domain2 AS "Domain Outgoing Anzahl"
| sort - Anzahl
| head 50