I want to correlate events between two index
Index=A
Index = B
There are multiple user field(user, src_user, dsuer) under Index A. I have to search user in index A which have signature=password retrieved and need to check the same user in Index B if there is successful login(action=success) in 30 sec duration when user has retrieved the password.
Thank you in advance.
Have you tried using JOIN command, as you have user as common field you can try using it.