Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How can I search for results that share the same Mac address?

$
0
0
I think I'm close. Just need a little help. here is my current search index=windows sourcetype=dhcpsrvlog | stats dc(raw_mac) as macCount values(raw_mac) as mac by dest_nt_host| eventstats count by raw_mac | where count = 2 I'm trying to get results for any 2 systems sharing the same mac address.

Viewing all articles
Browse latest Browse all 47296

Trending Articles