Filter ip with pie

(Nurhambali) #1

hi all,

i have problem with multi ip this is my logs :

attack.src_ip : 36.86.63.182, 223.202.110.11, 36.71.158.217, 182.30.24.21, 103.78.103.49, 180.252.157.49, 180.246.39.42, 139.224.18.42, 207.226.218.72, 223.202.110.11, 180.242.9.127

whe i create visualize metode terms , ican't sparate the ip attack.src_ip example:

i try add filter ip 223.202.110.11

how if i only filter ip 223.202.110.11 thast ip only , any ides my problem?

thanks,
hambali

(Josh Dover) #2

Unfortunately, Kibana's support of array fields is a bit lacking in some areas.

If the field on the document is an array, then if any filter matches that document, it will be included in the results (meaning all IPs will be shown).

There may still be a way to accomplish what you're trying to do, but I'm having a hard time understanding what you want the graph to be. If you were to filter by a single IP what do you want the pie chart to display?

(Nurhambali) #3

the problem's is i want when i click 1 result ip addrees in the pie kibana, i'am only want the result's is only this ip.

any ides is my problem's ?

thanks,
hambali

(system) closed #4

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.