I have a search that will return the last logged-on user, but I have to run this manually each time. I need to make a version of this using appendCols where I can insert "IP_from_parent_search" instead of the IP (i.e. 188.8.131.52):
search index=windows sourcetype="wineventlog:cef" 184.108.40.206 eventID=ZZZZ
| rex "duser=(?<duser>[^ ]*)"
| rex "dhost=(?<dhost>[^ ]*)"
| search dhost=220.127.116.11
| head 1
The IP (18.104.22.168) appears twice because at first I scan the raw to see if the IP is there. If so, I then look at the particular field (dhost) to see that the IP is there, AND, in the correct part of the event. But I have to manually do this search, and put in the IP.
The question is... how do I combine these? The results should look like: