For example: firewall logs that has the same IPs and ports in Windows of time 10 sec.
Solved
How do I aggregate multiple logs into a single output?
Best answer by pie
Start with the Aggregations function to select the desired data, and use the appropriate Aggregate function for your use case:
https://docs.cribl.io/stream/aggregations-function/
Aggregate events in real time
Sign up
Already have an account? Login
Login to the community
No account yet? Create an account
Using your Cribl Curious or University Account
User Login Employee loginEnter your E-mail address. We'll send you an e-mail with instructions to reset your password.
