将防火墙日志导入splunk
搜索drop信息相关信息:msg=*dropped*
source ip的归属地:相关函数 iplocation (iploc_len,iploc_log)
地理信息统计相关函数:geostats
host="*.*.*.*" msg=*dropped* | iplocation prefix=iploc_ allfields=true src | fields iploc_* | table iploc_* | geostats latfield=iploc_lat longfield=iploc_lon count by iploc_City