Stan Bradley
| append [| inputlookup append=t unmanaged_higher.csv in which cid=* MACPrefix!=not one LocalAddressIP4=* LocalAddressIP4!=none | rename ComputerName Once the “Past Found Because of the”| append [ inputlookup append=t unmanaged_med.csv where cid=* MACPrefix!=none LocalAddressIP4=* LocalAddressIP4!=none | rename ComputerName As “Past Receive Because of the”]| append [| inputlookup append=t unmanaged_lower.csv where cid=* MACPrefix!=none LocalAddressIP4=* LocalAddressIP4!=nothing | rename ComputerName Since the “Past Discover From the”] | append [| inputlookup notsupported.csv in which cid=* MACPrefix!=not one LocalAddressIP4=* LocalAddressIP4!=not one | rename ComputerName While the “Last Discover Of the” ] | eval “Last Seen (UTC)”=strfgo out(_day, “%m/%d/%y %I:%M%p”) | fillnull well worth=null assistance | eval LocalAddressIP4=mvsort(mvdedup(split(LocalAddressIP4,” “))) | eval discoverer_aid=mvsort(mvdedup(split(discoverer_help,” “))) | eval aip=mvsort(mvdedup(split(aip,” “))) | type 0 -“History Seen (UTC)” | research oui.csv MACPrefix Returns Manufacturer, ManufacturerAddress | fillnull worthy of=NA Company | eval Company=if(Manufacturer=”NA”,InterfaceDescription,Manufacturer) ]
|head one hundred |statistics count earliest(_time) given that very first because of the username sourcetype | eval first=strftime(first,”%m/%d/%y %H:%M:%S”) | eval username=lower(username) | stats amount from the username sourcetype first | dedup login name
| inputlookup managedassets.csv | eval “Last Viewed (UTC)”=strfbig date(_time, “%m/%d/%y %I:%M%p”) | types 0 -“History Viewed (UTC)” | lookup oui.csv MACPrefix Yields Name brand | fillnull really worth=NA Name brand | eval Manufacturer=if(Manufacturer=”NA”,InterfaceDescription,Manufacturer)
| sign-up support [| inputlookup assistance_grasp where cid=* | eval “Last Seen (UTC)”=strfbig date(_big date, “%m/%d/%y %I:%M%p”) | types 0 -“History Seen (UTC)” | search oui.csv MACPrefix Efficiency Brand name | fillnull well worth=NA Brand name | eval Brand=if(Manufacturer=”NA”,InterfaceDescription,Manufacturer) | dedup support]
| append [| inputlookup append=t unmanaged_large.csv where cid=* MACPrefix!=nothing LocalAddressIP4=* LocalAddressIP4!=not one | rename ComputerName Once the “History Discover Of the” | append [ inputlookup append=t unmanaged_med.csv in which cid=* MACPrefix!=none LocalAddressIP4=* LocalAddressIP4!=not one | rename ComputerName As the “History Discovered From the”] | append [| inputlookup append=t unmanaged_lowest.csv in which cid=* MACPrefix!=none LocalAddressIP4=* LocalAddressIP4!=none | rename ComputerName As the “History Discover Of the”] | append [| inputlookup notsupported.csv in which cid=* MACPrefix!=none LocalAddressIP4=* LocalAddressIP4!=not one | rename ComputerName As the “Past Discovered Because of the” ] | eval “Last Seen (UTC)”=strfbig date(_big date, “%m/%d/%y %I:%M%p”) | fillnull well worth=null support | eval LocalAddressIP4=mvsort(mvdedup(split(LocalAddressIP4,” “))) | eval discoverer_help=mvsort(mvdedup(split(discoverer_assistance,” “))) | eval aip=mvsort(mvdedup(split(aip,” “))) | types 0 -“History Viewed (UTC)” | look oui.csv MACPrefix Efficiency Brand, ManufacturerAddress | fillnull worthy of=NA Company | eval Brand name=if(Manufacturer=”NA”,InterfaceDescription,Manufacturer) ]
| append [|inputlookup aws_ec2_photo.csv] | append [|inputlookup aws_ec2_circumstances.csv] | append [|inputlookup aws_ec2_mac_ip_research.csv] | append [|inputlookup aws_ec2_networkacl_records.csv] | append [|inputlookup aws_ec2_networkacls.csv] | append [|inputlookup aws_ec2_networkinterface_privateips.csv] | append [|inputlookup aws_ec2_networkinterfaces.csv] | append [|inputlookup aws_ec2_securitygroup_regulations.csv] | append [|inputlookup aws_ec2_securitygroups.csv] | append [|inputlookup aws_ec2_subnets.csv] | append [|inputlookup aws_ec2_amounts.csv] | append [|inputlookup aws_ec2_vpcs.csv] | append [|inputlookup aws_iam_account_aliases.csv]