Hello, lets say I have events from two sourcetypes:
Now I want to match username to hostname based on the time and ip field in the following manner:
ip has to be the same, time has to be the closest time (before or after). Any easy out of the box way for doing that?
You could try using streamstats by ip to add recent usernames and recent hostnames to neighbouring events.
Whether that works depends on your data. For example, if you have this set at 12:10:
12:00 188.8.131.52 host=foohost 12:05 184.108.40.206 user=foouser 12:09 220.127.116.11 host=barhost
You would associate 12:05 with 12:09?
What if at 12:11 you get another event like this:
12:11 18.104.22.168 user=baruser
Would you now associate 12:05 with 12:00?