Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Blason_R
MVP Gold
MVP Gold
Jump to solution

Can I configure complex views using smart reporter?

Hello,

I am really curious whether complex operations can be visualized through views in Smart Console? I require a plot of source IP addresses that have communicated with destination IP addresses exceeding 20 GB within a single day. These should be grouped by destination address, excluding port 443 and UDP 53, and the destination addresses must not be RFC1918.

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
0 Kudos
2 Solutions

Accepted Solutions
PhoneBoy
Admin
Admin

From what I remember of SmartEvent, I don't think you can create a report like that.

View solution in original post

the_rock
MVP Gold
MVP Gold

Customer asked me that exact thing last year and TAC told me it was not possible. They did mention it could be doable possibly by exporting logs to external tool, but not via smart console.

Andy

View solution in original post

0 Kudos
4 Replies
PhoneBoy
Admin
Admin

From what I remember of SmartEvent, I don't think you can create a report like that.

the_rock
MVP Gold
MVP Gold

Customer asked me that exact thing last year and TAC told me it was not possible. They did mention it could be doable possibly by exporting logs to external tool, but not via smart console.

Andy

0 Kudos
Blason_R
MVP Gold
MVP Gold

Yeah that is right but then I built elaticsearch and started ingesting logs there to build a complex queries.

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
0 Kudos
the_rock
MVP Gold
MVP Gold

Yeah, you can do that. I had one of my colleagues show me, he is SIEM genius...lots of possibilites.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events