I have 2 sourcetypes: websense_ss and pan:traffic. I want to correlate these 2 sourcetypes with timestamp and IP Address of user(May 2 16:30:00 << This is timestamp pattern of data).
I'm try to merge 2 fields to 1 file because 2 sourcetypes have different fields, but it's the same data. Below are the details:
I want to compare 2 sourcetypes by correlate data with timestamp and ip address and get an output like this:
Output after correlation
Thank you so much
Sorry for my poor English
See if this gives you what you're looking for
For merging the 2 fields, you can use the coalesce function. Like this
your base search here | eval src_ip_wp=coalesce(src_ip, src_host)
To corelate the events based on this new IP and time, try this
your base search here | eval src_ip_wp=coalesce(src_ip, src_host) | stats list(_raw) by src_ip_wp _time
You can change _raw to the fields that you need.