Fetch VPN user details from one search and use the username to get details like email addresses from another search.
index=## host= ## sourcetype="##" source="#.log" eventtype=# parent session started
| table user host src_ip group
This lists details like:
user host src_ip group
bxxxx.gwwww x.x.x.x x.x.x.x Finance
I would like to add more details to the table like email address of the person and location which i can get from
Full_Legal_Name: Mr.ttt ccc
How do I take the user details from the first search like ( bxxxx.gwwww) and match it to the second search to get the email address and other info?
The only partially matching value between 2 searches is the users name , there are no field matches between both searches.
I will present a total of two methods.
First, the values from the first search are made into lookup files. After that, through lookup command, it connects to the second search and composes it into a table.
The second append or join command creates a matching part of different searches and organizes them into a table.
For more information on the search, please see the search reference manual or ask a question again.