I need to extract two different fields from two different events in two different index only if these two events have a common field value and occur in a specific time range. For example:
I want to draw a table with this info: username from index SRV, srcip and _time from index LB only if exchangecookie is the same in both events and the time spwn is less than 5 sec. In this case the output wil be:
10.49.00 bilbo.baggins 188.8.131.52
Time and src IP from EVENT 1 and username from EVENT 2. EVENT 3 must be ignored because have a different exchangecookie and EVENT 4 was indexed too late.
I've read about join but I don't think it's the solution.