I am building a dashboard based on all activity related to an IP. I have one source that generates events, but does not always include the IP. The events that do have an IP always have the host name. From one search, I want to search by IP, but also associate the IP to a host name and then search again with the host name and display all events.
You're looking for something like this?
source="mySourceType" [search source="mySourceType" myIPAddressField=192.168.53.105 | fields host]
that worked - thanks!