我正在寻找以下结果。
印度没有扫描仪 IP 被阻止
印度没有扫描仪 IP 非阻塞
印度的扫描仪 IP 被封锁
印度,扫描仪 Ip 未阻塞 where ip1,ip2=>Scannner IP
我已经尝试了以下一个..但它只显示“没有扫描仪 IP 被阻止的印度”计数
| eval BlockedStatus = case ( src !="ip1" OR src !="ip2.*" OR blocked=1,"india without scanner IP blocked", src !="ip1" OR src !="ip2*" OR blocked=0 ,"india without scanner IP nonblocked" ,src ="ip1" OR src ="ip2" OR blocked=1,"india with scanner IP blocked", src ="ip1" OR src ="ip2" OR blocked=0 ," india with scanner Ip non blocked ")
| stats count by eventtype,BlockedStatus
| rename eventtype as "Local Market",count as "Total Critical Events"