I have two searches index= windows EventCode=1234 Logon_Type=8 | table host | dedup host
and index=iis host=*|table host|dedup host
index= windows EventCode=1234 Logon_Type=8 | table host | dedup host
index=iis host=*|table host|dedup host
How to combine both these queries to display only the hosts which have that particular EventCode and Type and also in the IIS index.
Thanks in advance.
Try something like this
(index=windows EventCode=1234 Logon_Type=8) OR (index=iis host=*)
| stats values(index) AS index by host
The above query is displaying the hosts which is either in index=windows or index=iis. I am looking for a list of only the hosts which are present in both the indexes.