I hope the following makes sense...I have two indexes for separate application logs, index A and index B. I need help writing a search that will show me if a certain event in index B does not occur within 24 hours of an event in index A.
The search to find the event in index A is:
index=indexA sourcetype=sourcetype Network_Address="1.1.1.1" OR Network_Address="2.2.2.2" OR Network_Address="3.3.3.3"
| stats values(src) values(time) by user
The search to find the event in index B is:
index=indexB "eventCode" | stats values(id) values(time) AS id by user
So basically I want the search to show me all users who have an event in index A, along with the src and time from each event, but don't have an event in index B within 24 hours of the index A event.
I would suggest to use outputlookup to store results of the first query, then do the second search and use eval to make the calculation
I would suggest to use outputlookup to store results of the first query, then do the second search and use eval to make the calculation
Using mreynov's suggestion I piped the search in index A to a lookup table then used the following search to get my desired results
|inputlookup lookUpName.csv
| search NOT [search index=indexB "eventCode"
| fields user]