Thanks in advance.
I want to filter all the events with same source ip and destination ip's with different port numbers in a time interval of 15minutes.
srcip,dstip,dstport are the field names.
Can you please help me to achieve this.
Please let me know any of the options like visualization charts,searches or alert methods.