i'm trying to generate a search where i can summarize its info into a table. specifically i'm trying to detect link flapping caused by hosts having the same mac address across many/same switches.
in the logs i get one entry for each occurrence, sometimes its across different hosts; so i group the logs with a transaction on the dvc_mac (which i have set up as a field extraction):
"is flapping between port" | transaction dvc_mac
what i would like is a table where i can concatenate all the hosts seen for that single dvc_mac address, eg:
mac_address seen_on dvc_mac host1, host2...
is this possible?
woohoo! worked a treat; thanks Stephen!
to extend the question a little;
1) what if i wanted to also include the interfaces seen on the host? i have a multivalue field called 'int' such that i would like
mac_address seen_on dvc_mac hostA (intA1, intA2), hostB (intB1, intB2)...
2) if i wanted a frequency count of each dvc_mac
mac_address seen_on count dvc_mac hostA (intA1, intA2)... 4