Any reason why this can't be visualized in a geo cluster map? source="udp:514" index="syslog" NOT src_ip IN (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 17.0.0.0/8) action=DROP src_ip!="162.159.192.9...
Hi, I have created a Cluster Map that show number of counts based on number of ASA blocked actions. The circle size is based on number of hits. A bigger circle represent more c...
Hi All,
I need help building a SPL that would return all available fields mapped to their sourcetypes/source
Looking across all Indexers crawling through all indexes index=*
I currently u...
...estlookup. While it works the index and sourcetype does not line up with the results. Mapping I found handles this SPL a little different than a normal search, location of the stats c...
It appears that using now() inside of the map command will always return the time that the map was started rather than the time for each loop. The below SPL shows an example of this. Does anyone h...
Hello, I am trying to use one cluster map to visualize the locations of a user's source and destination IPs for Duo logs. Currently, I have two separate cluster maps for each. Source IP Address Q...
Could someone have a look at the following query and see why it does not give me the results I expect based on the documentation of map?
index=portal sourcetype=app:*** source="log" c...
I'm using the map command to iterate through a list of devices and forecasting some of the metrics associated with each device. That's all working but what I really want is to then average t...
I'm trying to look for refernce or documintation that shows me which fields in sysmon logs should be mapped to which fields in endpoint datamodel. for example Image & ParentImage it s...