Stan Bradley
| append [| inputlookup append=t unmanaged_large.csv where cid=* MACPrefix!=nothing LocalAddressIP4=* LocalAddressIP4!=not one | rename ComputerName Due to the fact “History Found By”| append [ inputlookup append=t unmanaged_med.csv in which cid=* MACPrefix!=nothing LocalAddressIP4=* LocalAddressIP4!=nothing | rename ComputerName Due to the fact “Past Receive Of the”]| append [| inputlookup append=t unmanaged_reduced.csv where cid=* MACPrefix!=none LocalAddressIP4=* LocalAddressIP4!=nothing | rename ComputerName While the “History Found Because of the”] | append [| inputlookup notsupported.csv where cid=* MACPrefix!=nothing LocalAddressIP4=* LocalAddressIP4!=not one | rename ComputerName Since the “History Located Of the” ] | eval “History Seen (UTC)”=strfgo out(_day, “%m/%d/%y %I:%M%p”) | fillnull value=null help | eval LocalAddressIP4=mvsort(mvdedup(split(LocalAddressIP4,” “))) | eval discoverer_aid=mvsort(mvdedup(split(discoverer_assistance,” “))) | eval aip=mvsort(mvdedup(split(aip,” “))) | type 0 -“Past Seen (UTC)” | research oui.csv MACPrefix Yields Name brand, ManufacturerAddress | fillnull well worth=NA Company | eval Name brand=if(Manufacturer=”NA”,InterfaceDescription,Manufacturer) ]
|direct 100 |stats amount basic(_time) due to the fact basic from the login name sourcetype | eval first=strftime(very first,”%m/%d/%y %H:%M:%S”) | eval username=lower(username) | statistics matter because of the login name sourcetype first | dedup login name
| inputlookup managedassets.csv | eval “Last Viewed (UTC)”=strftime(_day, “%m/%d/%y %I:%M%p”) | kinds 0 -“Last Viewed (UTC)” | look oui.csv MACPrefix Output Brand | fillnull worth=NA Brand | eval Brand name=if(Manufacturer=”NA”,InterfaceDescription,Manufacturer)
| register support [| inputlookup help_grasp where cid=* | eval “History Seen (UTC)”=strftime(_day, “%m/%d/%y %I:%M%p”) | sort 0 -“History Seen (UTC)” | look oui.csv MACPrefix Returns Manufacturer | fillnull worth=NA Manufacturer | eval Name brand=if(Manufacturer=”NA”,InterfaceDescription,Manufacturer) | dedup services]
| append [| inputlookup append=t unmanaged_large.csv in which cid=* MACPrefix!=none LocalAddressIP4=* LocalAddressIP4!=not one | rename ComputerName As “Last Discover By” | append [ inputlookup append=t unmanaged_med.csv in which cid=* datingmentor.org/widow-chat-rooms/ MACPrefix!=nothing LocalAddressIP4=* LocalAddressIP4!=none | rename ComputerName Because “Last Found By the”] | append [| inputlookup append=t unmanaged_reduced.csv in which cid=* MACPrefix!=none LocalAddressIP4=* LocalAddressIP4!=none | rename ComputerName Since the “History Found Of the”] | append [| inputlookup notsupported.csv where cid=* MACPrefix!=nothing LocalAddressIP4=* LocalAddressIP4!=not one | rename ComputerName Due to the fact “History Receive Because of the” ] | eval “Past Seen (UTC)”=strfday(_day, “%m/%d/%y %I:%M%p”) | fillnull well worth=null help | eval LocalAddressIP4=mvsort(mvdedup(split(LocalAddressIP4,” “))) | eval discoverer_help=mvsort(mvdedup(split(discoverer_services,” “))) | eval aip=mvsort(mvdedup(split(aip,” “))) | type 0 -“History Seen (UTC)” | lookup oui.csv MACPrefix Productivity Name brand, ManufacturerAddress | fillnull value=NA Brand name | eval Brand=if(Manufacturer=”NA”,InterfaceDescription,Manufacturer) ]
| append [|inputlookup aws_ec2_photographs.csv] | append [|inputlookup aws_ec2_days.csv] | append [|inputlookup aws_ec2_mac_ip_search.csv] | append [|inputlookup aws_ec2_networkacl_entries.csv] | append [|inputlookup aws_ec2_networkacls.csv] | append [|inputlookup aws_ec2_networkinterface_privateips.csv] | append [|inputlookup aws_ec2_networkinterfaces.csv] | append [|inputlookup aws_ec2_securitygroup_statutes.csv] | append [|inputlookup aws_ec2_securitygroups.csv] | append [|inputlookup aws_ec2_subnets.csv] | append [|inputlookup aws_ec2_quantities.csv] | append [|inputlookup aws_ec2_vpcs.csv] | append [|inputlookup aws_iam_account_aliases.csv]
155 | Parece | _Big date |
| inputlookup managedassets.csv | eval “Last Seen (UTC)”=strfdate(_date, “%m/%d/%y %I:%M%p”)| type 0 -“History Viewed (UTC)” | search oui.csv MACPrefix Output Name brand | fillnull really worth=NA Brand name | eval Brand name=if(Manufacturer=”NA”,InterfaceDescription,Manufacturer) | subscribe help [| inputlookup aid_learn where cid=* | eval “Past Viewed (UTC)”=strftime(_date, “%m/%d/%y %I:%M%p”) | type 0 -“History Viewed (UTC)” | lookup oui.csv MACPrefix Returns Brand | fillnull really worth=NA Brand name | eval Name brand=if(Manufacturer=”NA”,InterfaceDescription,Manufacturer) | dedup assistance] Stan Bradley| append [| inputlookup append=t unmanaged_higher.csv where cid=* MACPrefix!=none LocalAddressIP4=* LocalAddressIP4!=not one | rename ComputerName Because “History Found By the”| append [ inputlookup append=t unmanaged_med.csv in which cid=* MACPrefix!=none LocalAddressIP4=* LocalAddressIP4!=not one | rename ComputerName Once the “History Located Because of the”]| append [| inputlookup append=t unmanaged_lower.csv in which cid=* MACPrefix!=not one LocalAddressIP4=* LocalAddressIP4!=nothing | rename ComputerName Because “Last Receive Because of the”] | append [| inputlookup notsupported.csv where cid=* MACPrefix!=not one LocalAddressIP4=* LocalAddressIP4!=none | rename ComputerName As “Last Located By” ] | eval “Last Viewed (UTC)”=strfbig date(_day, “%m/%d/%y %I:%M%p”) | fillnull well worth=null services | eval LocalAddressIP4=mvsort(mvdedup(split(LocalAddressIP4,” “))) | eval discoverer_assistance=mvsort(mvdedup(split(discoverer_help,” “))) | eval aip=mvsort(mvdedup(split(aip,” “))) | type 0 -“History Viewed (UTC)” | search oui.csv MACPrefix Returns Brand, ManufacturerAddress | fillnull value=NA Manufacturer | eval Brand name=if(Manufacturer=”NA”,InterfaceDescription,Manufacturer) ] |
157 | CS | ComputerName |
event_simpleName=”ProcessRollup2″ ComputerName=COMPUTERNAME FilePath=”*Users*” Otherwise CommandLine=”*Users*” | rex job=FilePath form=sed “s/.*\bUsers\b.(\w+)(\b.*)/\1/g” | rex career=CommandLine form=sed “s/.*\bUsers\b.(\w+)(\b.*)/\1/g” | regex CommandLine!=”(?i).\b.” | regex FilePath!=”(?i).\b.” Stan BradleyI happened to be fortunate are increased to the a farm where I had a chance of a young age so you’re able to seem fish and you can pitfall, I spent much of my young people hunting squirrels, rabbits, frog gigging and you can powering turtle traces. We been deer search with my bow at age of 16 last year designated my personal 35th bend seasons about trees of Kentucky into the 1995 We decided to go to big games book university in Gunnison, Tx. I spent per year from then on going back family We become Turkey hunting therefore became one of my personal most significant appeal. Today I’m privileged as part-owner away from good turkey telephone call company . I deer look together with her regarding slip i poultry seem together on the springtime we bowfish with her in the summer just what far more should i request. |