Hi, I have a large set of data (firewall logs) that I'm trying to summarize. I've been able to write a script to consolidate the ports, now am looking to conslidate even further, based on IP.
Source Destination Type Port
192.168.5.108 192.168.11.12 TCP 1, 2, 3, 4, 5, 15
192.168.5.109 192.168.11.12 TCP 6, 7, 8, 9, 10, 11
192.168.5.110 192.168.11.12 TCP 12, 13
192.168.6.23 192.168.11.12 TCP 14, 15
192.168.5.108 192.168.11.13 TCP 10, 12, 13, 14, 15, 5
192.168.5.109 192.168.11.13 TCP 16, 17, 18, 19, 110, 111
192.168.5.110 192.168.11.13 TCP 112, 113
192.168.6.108 192.168.11.14 TCP 20, 22, 23, 24, 25, 6
192.168.6.109 192.168.11.14 TCP 26, 27, 28, 29, 210, 211
192.168.7.110 192.168.11.14 TCP 212, 213
192.168.6.23 192.168.11.14 TCP 214, 215
I'd like to script it so that the output would group all the source IP's, and their destination ports, going to the same destination IP:
SourceIP1,IP2,IP3,IP4 TCP DestinationIP DestinationPort1,P2,P3,P4,P5,P6......
example, the first destination of 192.168.11.12 would be summarized to look like so:
192.168.5.108,192.168.5.109,192.168.5.110,192.168.5.23 192.168.11.12 TCP 1, 2, 3, 4, 5, 15, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15
Any help would be greatly appreciated!