I am trying to search for events that contain one IP from each of the two groups of IP addresses. For instance:
index=main sourcetype=* | search ("10.10.10.10" OR "126.96.36.199" OR "188.8.131.52" OR "184.108.40.206" OR "220.127.116.11") AND ("18.104.22.168" OR "22.214.171.124" OR "126.96.36.199" OR "188.8.131.52")
I am not specifying the source type or fields because I also want to search through multiple source types.
I couldn't find an answer similar to this issue. I also looked at subsearches, but didn't see how they would solve this.
index=main sourcetype=* | lookup ips AS ips OUTPUT ips1 ips2 | mvexpand ips1 ips2 | stats values(_raw) count DC(ips) AS dc by ips1,ips2 | where dc==1
I can't test it since you don't have logs.