I want to build a table of alerts from and IDS where the rows are keyed on a term (alert name) then in the first column, the second column I want the alert category then I want then number of unique src IP addresses and the second column the number of dest IP addresses.
Ideally when you click on the src ip address count you drill down to a another visualisation with the IP addresses as key followed but count of alerts for that IP and so on down to the individual alert.
My first attempt at the top level table is below:
This is a long way from what I want and I am clearly on the wrong track.
Specifically I just want the count of unique terms in each column. That I can use to drill down to a lower level visualisation.
Can someone point me to some detailed documentation on building complex table visualisations. Everything I have found by searching is very simplistic. As are all the training videos. I would much prefer a written tutorial which describes how one is supposed to use the table building tool to build non trivial table.
I know how to construct a queries to do the aggregations necessary and could build the tables in a program but I would really not have to do that!
It is far from intuitive!