Hi all!
Is there a way to filter log entries in Smart Console for unique IPs?
For example: I needed to provide a list of improperly configured workstation clients. We recently had a desktop tech configure an old DNS server on some devices. This IP is getting blocked by the gateway, as it's no longer in production. My search query is "src:10.10.10.0/24 port:53" Of course, this will show every hit. I've been adding each IP to a "NOT" in the query to whittle down the list, but this is really inefficient ... especially on a /23!
Is there a way to only display unique source IPs in Smart Console log viewer?
We're on R81.20 and are in an enterprise environment with dedicated MDS/CP mgmt and log servers.
Or if there is a better way to pull this info, I'd gladly do it by a different method... maybe reports?
Thanks in advance!