記事:
クライアントの比較:
fields @timestamp, @message, `connection-attempt-status`, `connection-attempt-failure-reason`, username, `client-ip`, `device-type`, `device-ip` | filter `connection-attempt-status` = "successful" | sort @timestamp desc | limit 100 | display @timestamp, `connection-attempt-status`, `connection-attempt-failure-reason`, username, `client-ip`, `device-type`, `device-ip`
FIELDS @timestamp, @message, `connection-attempt-status`, username | FILTER `connection-attempt-status` = "successful" | stats count(*) as username_count by username | sort username_count DESC | display username, username_count
FIELDS @timestamp, @message, username | stats avg(`egress-bytes`) as egress_bytes by username, bin(5m) as time | sort time ASC | display time, username, egress_bytes
記事: