Hello, I have the following drilldown dataset. I cannot work out how to convert the 'bandwidth' column in to a 'browse time' column. Is anyone able to assist ? (I have attached a screenshot which shows how I would like it to be with a browse time column).
Thank you kindly if possible.
select coalesce(nullifna(`user`), nullifna(`unauthuser`), ipstr(`srcip`)) as user_src, app, sum(coalesce(`sentbyte`, 0)+coalesce(`rcvdbyte`, 0)) as bandwidth from $log where $filter and logid_to_int(logid) not in (4, 7, 14) and nullifna(app) is not null and (appcat = 'Social.Media') group by user_src, app order by bandwidth desc
Solved! Go to Solution.
Try:
select user_src, app, ebtr_value(ebtr_agg_flat(browsetime), null, $timespan) as browsetime from ###(select user_src, app, ebtr_agg_flat(browsetime) as browsetime from (select coalesce(nullifna(`user`), ipstr(`srcip`)) as user_src, app, ebtr_agg_flat($browse_time) as browsetime from $log where $filter and $browse_time is not null and (appcat = 'Social.Media') group by user_src, app) t group by user_src, app order by ebtr_value(ebtr_agg_flat(browsetime), null, null) desc)### t group by user_src, app order by browsetime desc
Hi there, please use predefined dataset "top-user-by-website-browsetime".
Regards,
hz
thank you kindly but how do I change out 'domain' for 'app' within that dataset ? Simply swapping the word 'domain' for 'app' does not work.
top-user-by-website select user_src, domain, ebtr_value(ebtr_agg_flat(browsetime), null, $timespan) as browsetime from ###(select user_src, domain, ebtr_agg_flat(browsetime) as browsetime from (select coalesce(nullifna(`user`), ipstr(`srcip`)) as user_src, coalesce(nullifna(hostname), ipstr(`dstip`)) as domain, ebtr_agg_flat($browse_time) as browsetime from $log where $filter and $browse_time is not null and (appcat = 'Social.Media') group by user_src, domain) t group by user_src, domain order by ebtr_value(ebtr_agg_flat(browsetime), null, null) desc)### t group by user_src, domain order by browsetime desc
Try:
select user_src, app, ebtr_value(ebtr_agg_flat(browsetime), null, $timespan) as browsetime from ###(select user_src, app, ebtr_agg_flat(browsetime) as browsetime from (select coalesce(nullifna(`user`), ipstr(`srcip`)) as user_src, app, ebtr_agg_flat($browse_time) as browsetime from $log where $filter and $browse_time is not null and (appcat = 'Social.Media') group by user_src, app) t group by user_src, app order by ebtr_value(ebtr_agg_flat(browsetime), null, null) desc)### t group by user_src, app order by browsetime desc
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.