Skip to main content

For example: firewall logs that has the same IPs and ports in Windows of time 10 sec.

Start with the Aggregations function to select the desired data, and use the appropriate Aggregate function for your use case:

https://docs.cribl.io/stream/aggregations-function/
Aggregate events in real time


Reply