Skip to main content

Dropped logs-Metrics

  • March 25, 2025
  • 1 reply
  • 24 views

Forum|alt.badge.img+8

Hello , anyone have developed a dashboard using query formatted in YARA-L ? i'm looking to develop a dashboard to visualise dropped logs count for each log type ? 
Who can help please ?

1 reply

mikewilusz
Staff
Forum|alt.badge.img+10
  • Staff
  • March 25, 2025

This query should get you what you're looking for.

ingestion.log_type != "" $log_type = ingestion.log_type match: $log_type outcome: $drop_count = sum(ingestion.drop_count) order: $drop_count desc

-mike