i need to take the events from this search
that have the field Source_Network_Address into the field DestinationIP of the search eventtype="searchIPS2" Direction="Inbound" Severity="Medium"
eventtype="searchIPS2" Direction="Inbound" Severity="Medium"
how can i do this?
thanks to all who can help me
eventtype=searchIPS2 Direction=Inbound Severity=Medium [ search sourcetype=wmi:wineventlog:security Source_Network_Address=* | fields Source_Network_Address | rename Source_Network_Address as DestinationIP ]
View solution in original post