Hello everyone,
Someone may already be doing the output of grouped events with the definition of location by ip.
How not to lose location data when grouping events ?
In my request spl it is
| search......
|stats count(tunnelid) as sessioncount, values(StartTime) as StartTime, values(tunnelid) as tunnelid, values(tunnelip) as tunnelip, values(remip) as remip, values(vendor_action) as vendor_action by user
| iplocation remip
Of course, when displaying one type, the location IP is displayed.
How to display data on the location of each IP in grouped events ?
Apparently, the iplocation command can't handle a multi-value field. Try putting iplocation before stats.
| search......
| iplocation remip
| stats count(tunnelid) as sessioncount, values(*) as * by user