Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Search:
- index=foo | dedup 1 host sortby -_time |rex field=host "(?P<device>.*)" | stats count by staticIP device| lookup networks device OUTPUT network | where cidrmatch(network,staticIP)
- Lookup:
- device, network
- Router0, 10.0.0.0/8
- Router1, 132.10.0.0/16
- Router1, 188.2.0.0/16
- Router2, 89.0.0.0/8
- Router3, 192.168.0.0/16
- Router4, 26.3.0.0/16
- Results:
- staticIP device count network
- 26.3.55.0 Router4 1 26.3.0.0/16
- 192.168.0.0 Router3 1 192.168.0.0/16
- 192.168.128.0 Router3 1 192.168.0.0/16
- 89.128.0.0 Router2 1 89.0.0.0/8
- There are results missing for Router1, it should show 132.10.0.0 and 188.2.30.0.
- If I remove one of the Router 1 entries, I get the following
- staticIP device count network
- 26.3.55.0 Router4 1 26.3.0.0/16
- 192.168.0.0 Router3 1 192.168.0.0/16
- 192.168.128.0 Router3 1 192.168.0.0/16
- 89.128.0.0 Router2 1 89.0.0.0/8
- 188.2.30.0 Router1 1 188.2.0.0/16
- Note the entry for Router1
Add Comment
Please, Sign In to add comment