I created a search with the results I need, and then right-click IPv4 field to “show top values”. The result is an overview of IPv4’s I want to block, sorted on number of occurrences. Now i am trying to export those aggregated results to csv, so I can process then further. (block them on my firewall)
But the “Aggregating count() by IPV4” actions menu has no “export to csv” option, just “edit”, “duplicate”, “copy to dashboard”, and “delete”.
Top right of the search result has an export to csv option, but that’s not on the aggregated results, but on the global (non-aggregated) search results.
Surely I am missing something. There must be a way to export the displayed aggregated_count_by_IPv4 results to csv?
But I don’t have the export button for my aggregated search searchs. I feel really stupid, and probably miss something very basic. See this screenshot:
I know the “export to csv” option on the right top three-dot menu, but selecting that export gives: “You need to create a message table widget to export its result.”
Again… I feel stupid, but how can I export the aggregated search results in my screenshot?
Apologies for persisting, but what you show above, i think, is the way to export “All messages”, and not the aggregated search results…? I am looking for an export in this format:
IPV4 Count
1.2.3.4 100
5.6.7.8 65
As the above (aggregated) export format will allow me to add IPs easily to my firewall.
Meanwhile I have upgraded graylog from 3.3 to 4.2, but it doesn’t make a difference in this respect.
Again: I really appreciate the feedback here!
Selecting ‘export’ from the right top three button menu, gives this result:
And I really cannot find the option to “export to CSV” in the aggregated result message table action menu.
You may have missed some of the steps that @gsmith posted - I just followed them and was able to pull and export of usernames with IP’s against my test data. Did you make sure to save the search you created with the custom aggregate before trying the export?
EDIT: Didn’t think to look at the question
Since you are exporting anyway to load to the firewall, create the query to get the field data you want and get instance count via excel as you are adjusting the data for the import.
Or if you are just looking for top ~15 just drag select the resulting aggregate, copy to your clipboard and paste it to a file for further massaging.
I understand now. Yeah the example I gave above does have a filter for ALL messages but does not have the count per IPV4.
Actually that would be a nice feature to have in Saved Search’s or Dashboard Widgets which is to download an aggregated search results into a CVS with a count. Perhaps posting here for a feature request.
Could you confirm that you understand the feature request…? As it took a while before I was able to explain my issue properly here…
(i would like the developers to easily understand what I mean)