I would like to aggregate results but instead of using the typical "stats" functions (avg, first, last, ...) I would like to obtain the list of values of that field. Is it possible?
To illustrate what I want probably an example will help.
Suppose I have the following search results:
Event User IP
Failed login Test 18.104.22.168
Failed login Test 22.214.171.124
Failed login Test 126.96.36.199
Failed login Test 188.8.131.52
I would want to aggregate them to obtain something like this:
Event User ListOfIP
Failed login Test 184.108.40.206, 220.127.116.11, 18.104.22.168, 22.214.171.124
Is it possible?
Please sign in to leave a comment.