1、Lab Exercise 2 – Beyond Search Fundamentals
1.1、搜索:index=web sourcetype=access_combined
| table clientip action status
2、Lab Exercise 3 – Commands for Visualizations
2.1、搜索:index=security sourcetype=linux_secure vendor_action=failed
2.2、搜索:sourcetype=linux_secure vendor_action=failed
| chart count over vendor_action by src_ip #创建图表,通过ip展示每一个的动作
2.3、搜索:index=security sourcetype=linux_secure vendor_action=failed
| chart count over vendor_action by src_ip useother=f #将other去除掉
2.4、搜索: