...essage and correlate between two. I am looking for numbers 272 and 1,856 from HERE and looking for sample1 and sample2 from THERE
both HERE and THERE will have 272 common and that is the only one....
Hello peeps,
Does anyone know a better accelerator command that can help to correlate data? Im trying to correlate proxy server logs and AD logs. Please see my base search;
(index=p...
Hello,
Help me please. I'd like to define multiple search or subsearch to merge all relevant information about alerts.
Interesting fields in search are the hosts - as managed_host field and...
Hello, Our environment has this linux server that continually get's hit with Brute force attacks. I am trying to figure out where they are coming from. Since our servers are behind a nated firewall ...
...ther than “success” in our ldap logs: index=ldap sourcetype="openldap:access" err!=0 Unfortunately, we can't find a way correlate this event with other events in order to find the username a...
I want to correlate the login events of aws console to login events of cyberark. people login to aws console via cyberark. so need to correlate the login events of aws with cyberark, that i...
Hello, Having defined multiple alerts before starting to use Enterprise Security, is there a way to convert the existing alerts to correlation searches ? Instead of sending emails as a...
Hi Splunkers. I'm looking for a way to delete a correlation search that has been created with the wrong name (as ES doesn't let you rename them). The CS is currently disabled but I don't see a w...
Sorry for not spelling the problem out in the title, I'm a bit stuck even for the correct language to describe my puzzle. It's best I explain...
I have one index full of log data like the followin...
I have two events:
Event 1:
transactionId=123 field_x=x_value
Event 2
transactionId=123 status=success
How can I correlate these two?
I want to create a timechart for “field_x” when “s...