We need to generate a report with a list of unique IPs featuring on all logs for a given time period.
Have tried using Chart builder, this is the query for unique IPs and destination ports grouped by IP Address
select `srcip`, string_agg(distinct (`dstport`)::text, ' ') as dstport__agg_ from ###(select `srcip`, `dstport` from $log where $filter and (logflag&1>0) group by `srcip`, `dstport`)### t group by `srcip`
Is there any way to add the first and last times the IP featured in the logs with this?
I am trying to build a table with the following columns:
First seen time
Last seen time