I have a search that returns a set of source and dest IP addresses.
Index= ..... | table src, dest
I want to check these against the ip_intel feed.
I can see the ip_intel feed is populated
| `ip_intel` | search ip=*
How do I use the lookup commands to check against the ip_intel feeds ?
Can you try something :
index=<indexname> .. [|inputlookup ip_intel | return ip] | table src, dest | where src=ip OR dest=ip