Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Need to create an Alert to trigger when access to a list of internal IP's from external host source

$
0
0
I tried the following, sourcetype="cisco:*" [|inputlookup Testlist.csv | fields scr_ip | rename scr_ip AS dest_ip] | stats count by src_ip | sort desc - count

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>