I am trying to search for events that contain one IP from each of the two groups of IP addresses. For instance:
index=main sourcetype=* |
search ("10.10.10.10" OR "30.30.30.30" OR "50.50.50.50" OR "70.70.70.70" OR "90.90.90.90") AND
("20.20.20.20" OR "40.40.40.40" OR "60.60.60.60" OR "80.80.80.80")
I am not specifying the source type or fields because I also want to search through multiple source types.
I couldn't find an answer similar to this issue. I also looked at subsearches, but didn't see how they would solve this.
index=main sourcetype=* | lookup ips AS ips OUTPUT ips1 ips2 | mvexpand ips1 ips2 | stats values(_raw) count DC(ips) AS dc by ips1,ips2 | where dc==1
I can't test it since you don't have logs.
is it possible for you to share some sample data and sample output of what you're looking for? scrubbed of pii/phi?
Negative. Company policy.