I tried various combinations but failed
1. index="flowintegrator" src_port=21
|eval thisUser=src_ip + "="+ dest_ip
| timechart avg(bytes) as volume by
thisUser|predict thisUser
2. index="flowintegrator" src_port=21
|eval thisUser=src_ip + "="+ dest_ip
| timechart avg(bytes) as avg_bytes
by thisUser|predict avg_bytes
This works but I can't predict.
index="flowintegrator" src_port=21 |eval thisUser=src_ip + "="+ dest_ip | timechart avg(bytes) as avg_bytes by thisUser
Help
↧