I have this query that counts distinct users and groups them by VPN device. The counts for each is fine but I would like the TOTAL to be a separate field showing the sum of all users connected.
| where msg = "Client Type: Cisco AnyConnect VPN Agent for Windows 4.10.05085"
| count_distinct (user) as device_conn group by host,device_conn | total device_conn
Please sign in to leave a comment.