I tried the following,
sourcetype="cisco:*" [|inputlookup Testlist.csv | fields scr_ip | rename scr_ip AS dest_ip] | stats count by src_ip | sort desc - count
↧
Need to create an Alert to trigger when access to a list of internal IP's from external host source
↧