Splunk Search

Event correlation between two index

sgambhir0109
Loves-to-Learn Lots

I want to correlate events between two index

Index=A

Index = B

There are multiple user field(user, src_user, dsuer) under Index A. I have to search user in index A which have  signature=password retrieved and need to check the same user in Index B if there is successful login(action=success) in 30 sec duration when user has retrieved the password.

 

Thank you in advance.

Labels (1)
0 Karma

shugup2923
Path Finder

Have you tried using JOIN command, as you have user as common field you can try using it.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...