I need to see the location of the ip for each log

Comments

1 comment

  • Avatar
    Rick Jury

    Hi Aaronisa,

    you can remove a column from the final table with:
    | fields -_count

     

    For your second question you have some options there:

    1. you can do a lookup by ipaddress but not do a | count by ipaddress. This will just add the geo lookup fields to the raw unaggregated mesages.

    2 You could combine a summary table with more fields say like this:

    | count by ipAddress,eventtype,eventname. //etc any other fields include here
    | lookup latitude, longitude, country_code, country_name, region, city, postal_code from geo://location on ip = ipAddress
    | where !isNull(latitude)
    | sum(_count) as _count by latitude, longitude, country_code, country_name, region, city, postal_code,eventtype,eventname // etc add same fields here you added earlier
    | sort by _count | fields -_count

    0
    Comment actions Permalink

Please sign in to leave a comment.