Slide 72
Slide 72 text
72 13
Elasticsearch DSL
{"query":{"filtered":{"filter":{"and":[{"range":{"meta_ts":
{"gte":"2016-01-26T17:00:00.000Z","lte":"2016-02-02T17:10:20.
478Z"}}},{"term":{"class":"bro_conn"}},{"terms":{"dstipv4":
{"index":"lists","type":"indicator","id":"external_citrix_s
ervers","path":"values","cache":false}}},{"terms":
{"srccountrycode":["ru","cn","ir"],"execution":"or"}},
{"term":{"connstate":"sf"}},{"limit":{"value":
208333}}]}}},"aggs":{"groupby:duration_rcvdipbytes_dstport":
{"terms":{"lang":"native","script":"join","params":
{"fields":["duration","rcvdipbytes","dstport"],"separator":",
"},"size":200,"min_doc_count":1,"order":
{"_count":"desc"}}}},"size":10,"from":0,"timeout":120000}