Parse Cisco router logs

Comments

1 comment

  • Avatar
    Kevin Keech

    Hi Kenny,

    You will need to use the parse regex operator to first pull the port value from your log messages. Once you have this you can use the "count" or "count_distinct" operators to get a count by port number or count of distinct ports.

    For example using your supplied sample log you can run the following to get a count by destination port number

    | parse regex "->\s+\d{1,3}.\d{1,3}.\d{1,3}.\d{1,3}((?<dest\_port>\d+)),"

    | count by dest_port

    OR you can run the following to get a count of the distinct ports

    | parse regex "->\s+\d{1,3}.\d{1,3}.\d{1,3}.\d{1,3}((?<dest\_port>\d+)),"

    | count_distinct(dest_port) as distinct_ports

    0
    Comment actions Permalink

Please sign in to leave a comment.