I have a complex search that I need to do.
An example is something like:
CONDITION=(ip.dst=lots of different IPs' && port=some interesting ports && ip.src != some more Ip's)
What I would like to know is when condition is true.
If I run this search over many events over a long period, then it will take a long time.
Is there anyway I can tag my events as they are being indexed so that I can do a search on CONDITION=True, so that searching just needs to lookup for some meta "CONDITION=true", rather than having to evaluate the whole condition against each event.
So there are a few ways you could accomplish this (that I can think of):
You could also maybe use a summary index or there are probably other good ways that people can think of.
Looking at your query at a high level, seems that your underlying data can be mapped to Network Traffic datamodel and if that can be mapped, you can get DM acceleration and use tstats to run search for a longer time window with little to minimal impact on resources.