Skip to main content
Olav
New Member
December 9, 2014
Solved

Error with custom dataset after upgrade

  • December 9, 2014
  • 2 replies
  • 3465 views

Hi, after upgrading FAZ to 5.2.0 we have a problem with an customized dataset. When running a test query we get an error.

 

This is the query:

SELECT srcip, msg, service, dstip, count(*) as totalnum

FROM $log

WHERE $filter AND srcip IS NOT LIKE '10%' AND (subtype='violation' or action='deny')

GROUP BY srcip, msg, dstip, service

ORDER BY totalnum DESC

 

Log Type is set to "traffic"

 

The error we get: ERROR: syntax error at or near "LIKE"

 

We want to report all blocked outgoing traffic from inside. The filter on "LIKE '10%' " is essential for the report.

Does anybody how to solve this in 5.2.0?

 

Regards, Olav

    Best answer by hzhao_FTNT

    Hi Olav,

     

    In 5.2.0, ip has to be convert from inet to string by ipstr(). Your query will be:

    SELECT ipstr(srcip) as srcip, msg, service, ipstr(dstip) as dstip, count(*) as totalnum FROM $log WHERE $filter AND ipstr(srcip) NOT LIKE '10%' AND (subtype='violation' or action='deny') GROUP BY srcip, msg, dstip, service ORDER BY totalnum DESC

     

    Regards,

    hz

    2 replies

    hzhao_FTNT
    Staff
    Staff
    December 9, 2014

    Hi Olav,

     

    In 5.2.0, ip has to be convert from inet to string by ipstr(). Your query will be:

    SELECT ipstr(srcip) as srcip, msg, service, ipstr(dstip) as dstip, count(*) as totalnum FROM $log WHERE $filter AND ipstr(srcip) NOT LIKE '10%' AND (subtype='violation' or action='deny') GROUP BY srcip, msg, dstip, service ORDER BY totalnum DESC

     

    Regards,

    hz

    Olav
    OlavAuthor
    New Member
    December 10, 2014

    Hi hz,

    thank you for your fast answer. The problem was solved!

     

    Greetz,

    Olav

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!