im sorry. i did not have the full query. this is the one as it runs now sourcetype=snort NOT (signature_id=129:7:1 OR signature_id=124:1:1 OR signature_id=142:1:1 OR signature_id=124:7:1 OR signature_id=129:18:1 OR signature_id=129:8:1) [search sourcetype=snort (signature!="(spp_sip)*" (src_ip!=10.10.21.11 AND signature!="*POP3*") AND (src_ip!=10.108.246.111 OR 10.108.243.112 OR 10.108.243.113 OR 10.108.243.114 OR 10.108.243.115 OR 10.108.243.116) AND signature_id!=125:1:1) |top limit=20 src| table src] | stats count, values(signature) as Sigs by src | sort -count | lookup dnslookup clientip as src OUTPUT clienthost as DST_RESOLVED | iplocation src | fields src, count, Country, DST_RESOLVED, Sigs | rename src as "Source IP", count as Count, DST_RESOLVED as "DNS Resolution", Sigs as Signatures
... View more