I am running a search against my windows event logs, lets call it sourcetypeA. I need to use the IP address obtained form sourcetypeA to lookup up the host information from sourcetypeB. The end result needs to display the timestamp and other information from sourcetypeA and use the host information from sourcetypeB. Subsearching so far has not seem to resolve the problem. I merely need to use sourcetypeB as sort of a lookup table to plugin the host information found.
Hi
you could try something like:
index=<your index> (sourceteype=A OR sourcetype=B)
| eval hostA=if(sourcetype=="A", host,null()), hostB=if(sourcetype="B", host, null())
| stats earliest(_time) as _time values(*) as * by src
| table _time src hostB <other fields from sourcetypeA>
Where src is IP Address.
r. Ismo