Report on Hosts

This tool allows you to generate a report on the breakdown of a value present on the Hosts returned by your query. For example, to generate a report on ports seen on Hosts with HTTP services, you could query for services.service_name: HTTP and then generate a report on the breakdown of the field services.port


Report for Hosts


services.service_name services
HTTP 1,462 46.52%
MODBUS 577 18.36%
CODESYS 282 8.97%
S7 155 4.93%
SSH 125 3.98%
IEC60870_5_104 101 3.21%
TELNET 79 2.51%
FTP 70 2.23%
UNKNOWN 58 1.85%
VNC 56 1.78%
NTP 51 1.62%
PPTP 29 0.92%
FOX 17 0.54%
DNS 12 0.38%
SNMP 10 0.32%
EIP 9 0.29%
OPENVPN 7 0.22%
SMTP 7 0.22%
NETBIOS 6 0.19%
RTSP 6 0.19%
FINS 5 0.16%
MSSQL 5 0.16%
PCWORX 3 0.1%
BACNET 2 0.06%
DNP3 1 0.03%
IPP 1 0.03%
MIKROTIK_BW 1 0.03%
MMS 1 0.03%
MQTT 1 0.03%
PC_ANYWHERE 1 0.03%
RDP 1 0.03%
RSYNC 1 0.03%
TFTP 1 0.03%
Total 3,143 100.0%

JSON Report


{
  "total": 3143,
  "total_omitted": 0,
  "potential_deviation": 0,
  "buckets": [
    {
      "key": "HTTP",
      "count": 1462
    },
    {
      "key": "MODBUS",
      "count": 577
    },
    {
      "key": "CODESYS",
      "count": 282
    },
    {
      "key": "S7",
      "count": 155
    },
    {
      "key": "SSH",
      "count": 125
    },
    {
      "key": "IEC60870_5_104",
      "count": 101
    },
    {
      "key": "TELNET",
      "count": 79
    },
    {
      "key": "FTP",
      "count": 70
    },
    {
      "key": "UNKNOWN",
      "count": 58
    },
    {
      "key": "VNC",
      "count": 56
    },
    {
      "key": "NTP",
      "count": 51
    },
    {
      "key": "PPTP",
      "count": 29
    },
    {
      "key": "FOX",
      "count": 17
    },
    {
      "key": "DNS",
      "count": 12
    },
    {
      "key": "SNMP",
      "count": 10
    },
    {
      "key": "EIP",
      "count": 9
    },
    {
      "key": "OPENVPN",
      "count": 7
    },
    {
      "key": "SMTP",
      "count": 7
    },
    {
      "key": "NETBIOS",
      "count": 6
    },
    {
      "key": "RTSP",
      "count": 6
    },
    {
      "key": "FINS",
      "count": 5
    },
    {
      "key": "MSSQL",
      "count": 5
    },
    {
      "key": "PCWORX",
      "count": 3
    },
    {
      "key": "BACNET",
      "count": 2
    },
    {
      "key": "DNP3",
      "count": 1
    },
    {
      "key": "IPP",
      "count": 1
    },
    {
      "key": "MIKROTIK_BW",
      "count": 1
    },
    {
      "key": "MMS",
      "count": 1
    },
    {
      "key": "MQTT",
      "count": 1
    },
    {
      "key": "PC_ANYWHERE",
      "count": 1
    },
    {
      "key": "RDP",
      "count": 1
    },
    {
      "key": "RSYNC",
      "count": 1
    },
    {
      "key": "TFTP",
      "count": 1
    }
  ],
  "query": "(not services.truncated: true and services.service_name: {ATG, BACNET, CITRIX, CODESYS, DIGI, DNP3, EIP, FINS, FOX, GE_SRTP, IEC61850_5_104, MODBUS, PCWORX, PRO_CON_OS, S7, WDRPC}) and location.city=`Istanbul`",
  "field": "services.service_name"
}