|
Currently started using the geoASN app with the maxmind db's and it's working great on our sourcetypes with ip's, and | geoip lookups etc. What's the best way to report on only certain countries/cities that I am watching. Say i have a list of 50-100 countries or cities Maybe pass a inputlookup with those listed countries? Just curious best way to handle this. Current search being used is: sourcetype="access_combined" | lookup ga ip as clientip | stats count by country, org | sort - count |