Skip to content

Instantly share code, notes, and snippets.

What would you like to do?

The interesting part of this search is the lookup!

`autoreg_registrations` | lookup local=t mac2huid mac AS src_mac  | search NOT os=unknown | chart count by os

The autoreg_registrations macro expands to this:

index=ns-os sourcetype=autoreg source="/var/log/autoreg/applog" eventtype="network-registration-success"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.