I have searched through the knowledge base and have tried a number of things to fix my issue. I have not found my answer....so I am asking for help:
I created a lookup table file using a CSV called "shunlist.csv".
shunlist.csv format (first 5 lines):
srcip,timestamp,info
1.34.83.14,2015-09-11 06:02:53,SSH Brute Force
1.93.11.145,2015-09-03 15:50:58,RA SCAN Unusually fast Terminal Server Traffic Inbound
1.93.20.160,2015-09-15 19:30:40,RA SCAN Unusually fast Terminal Server Traffic Inbound
1.233.92.197,2015-09-06 19:52:15,SSH Brute Force
The following commands work fine:
| inputlookup shunlist.csv| table *
| inputlookup shunlist.csv | format
When I search using the following command, I get results, but I do not see the info field (from the CSV file) in the list of fields:
index=aws-flowlogs source=aws-flowlog dstaddr!=10.0.0.0/8 action=ACCEPT [| inputlookup shunlist.csv | rename srcip as dstaddr | fields + dstaddr]
I try this command and I only see the srcaddr and dstaddr fields. The info field does not show up.
index=aws-flowlogs source=aws-flowlog dstaddr!=10.0.0.0/8 action=ACCEPT [| inputlookup shunlist.csv | rename srcip as dstaddr | fields + dstaddr] | fields srcaddr dstaddr info
Any assistance will be appreciated. Thanks!
... View more