-
Notifications
You must be signed in to change notification settings - Fork 91
Open
Labels
ksqlDBksqlDB relatedksqlDB relatedrecipeuse caseA tutorial with an extended business use caseA tutorial with an extended business use case
Description
Snippet:
CREATE TABLE packetbeat_flows_by_1m WITH (KEY_FORMAT='JSON') AS
SELECT
source -> ip as srcip,
source -> port as srcport,
destination -> ip as dstip,
destination -> port as dstport,
network -> transport,
SUM(source -> packets) as source_packets,
SUM(source -> bytes) as source_bytes,
SUM(destination -> packets) as destination_packets,
SUM(destination -> bytes) as destination_bytes,
SUM(network -> packets) as network_packets,
SUM(network -> bytes) as network_bytes,
COUNT(*) as cnt
FROM packetbeat_flows
WINDOW TUMBLING (SIZE 1 MINUTE)
GROUP BY source->ip, source-> port, destination->ip, destination->port, network->transport
EMIT CHANGES;
Metadata
Metadata
Assignees
Labels
ksqlDBksqlDB relatedksqlDB relatedrecipeuse caseA tutorial with an extended business use caseA tutorial with an extended business use case
Type
Projects
Milestone
Relationships
Development
Select code repository
Activity
[-]Analyze Packbeat flows[/-][+]Cybersecurity: Analyze Packbeat flows[/+]