SHARE
TWEET

Untitled

a guest Dec 11th, 2019 89 Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. index=pa sourcetype=pan:threat raw_category = "web-advertisements" src IN (10.0.0.0/8, 192.168.0.0/16, 172.16.0.0/12)
  2. | stats count by src
  3. | rename src AS device.ip
  4. | join device.ip [search index=netvuln sourcetype=darktrace | stats values(device.hostname), values(device.macaddress), values(device.os), values(breachUrl), values(model.name), values(model.tags{}), values(triggeredComponents{}.triggeredFilters{}.trigger.value
  5. ), values(triggeredComponents{}.triggeredFilters{}.filterType), values(device.typename), values(device.tags{}.name) by device.ip | fields device.ip, values(device.hostname), values(device.macaddress), values(device.os), values(breachUrl), values(model.name), values(model.tags{}), values(triggeredComponents{}.triggeredFilters{}.trigger.value), values(triggeredComponents{}.triggeredFilters{}.filterType), values(device.typename), values(device.tags{}.name)]
  6. | sort device.ip DESC
RAW Paste Data
We use cookies for various purposes including analytics. By continuing to use Pastebin, you agree to our use of cookies as described in the Cookies Policy. OK, I Understand
 
Top