shell-whiz-toolkit/elasticsearch/README.md
2019-02-20 11:37:28 -08:00

6 lines
230 B
Markdown

# Elastalert hacks
```
curl -s logs.HOST.com:9200/logstash-2017.09.08/_search\?q=ty_params.ProcessName:osqueryd\&size=10000\&sort=@timestamp:desc | jq -r '.hits.hits[]._source.ty_params.Username' | sort | uniq -c | sort -nr
```