I have an index that has vulnerabilities that are affecting hosts.
Fields in the index are:
host, VulnID, VulnName
I have a lookup name Assets. It has field name DNS. This field DNS is to be used as host in index's query. e.g.
| stats .........
| lookup Assets DNS AS host .....
I need a query that gives me attached image results with fast performance because I have a lot of affected hosts with a lot of vulnerabilities. I will be using this query to create a scheduled report so I can reference this report in my dashboard to create panels. My query will be looking at a few days back based on my scans: