<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Something aking to | sort | uniq -c | sort -nr in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/something-aking-to-sort-uniq-c-sort-nr/m-p/436864#M96307</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/14162"&gt;@jackd&lt;/a&gt;&amp;nbsp;I presume you are referring to the traffic log query engine on the farewell/Panorama and&amp;nbsp; yes, it is not very advanced and distinct or uniq function are definitely missing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We use external SIME solution with advanced queries capabilities, but for&amp;nbsp; a small tasks I would export the logs and use Unix or some script to query them. You can also use the firewall local reporting engine to generate something similar. For example you can create a report on only unique source IPs hit count over a period of time, but this also has its limitation.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 27 Sep 2021 13:36:27 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2021-09-27T13:36:27Z</dc:date>
    <item>
      <title>Something aking to | sort | uniq -c | sort -nr</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/something-aking-to-sort-uniq-c-sort-nr/m-p/432477#M95747</link>
      <description>&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Like the title says, is there a way to run a filter for a period of time, pull out a list of IPs, sort them, remove the duplicates with a count, and sort them by most popular?&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;This is a common &lt;FONT color="#333300"&gt;&lt;A href="https://omegle.club" target="_blank" rel="noopener"&gt;omegle&lt;/A&gt; &lt;/FONT&gt;thing to do with syslog data, say you have a very permissive rule and you want to see what source IPs are being used by that rule. You could awk print the source IP column and filter it accordingly. How are you folks working with data like this?&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;&lt;FONT color="#000000"&gt;&lt;A href="https://azar.pro" target="_blank" rel="noopener"&gt;azar&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 07:08:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/something-aking-to-sort-uniq-c-sort-nr/m-p/432477#M95747</guid>
      <dc:creator>Jack45</dc:creator>
      <dc:date>2021-09-28T07:08:33Z</dc:date>
    </item>
    <item>
      <title>Re: Something aking to | sort | uniq -c | sort -nr</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/something-aking-to-sort-uniq-c-sort-nr/m-p/436864#M96307</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/14162"&gt;@jackd&lt;/a&gt;&amp;nbsp;I presume you are referring to the traffic log query engine on the farewell/Panorama and&amp;nbsp; yes, it is not very advanced and distinct or uniq function are definitely missing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We use external SIME solution with advanced queries capabilities, but for&amp;nbsp; a small tasks I would export the logs and use Unix or some script to query them. You can also use the firewall local reporting engine to generate something similar. For example you can create a report on only unique source IPs hit count over a period of time, but this also has its limitation.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 13:36:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/something-aking-to-sort-uniq-c-sort-nr/m-p/436864#M96307</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2021-09-27T13:36:27Z</dc:date>
    </item>
  </channel>
</rss>

