Hi,
I want to know if there is a way to pass parent search field value as source/input for sub-search for a different sourcetype and then stats its field.
e.g) we have an index=risk and the field value extracted from there is Image_Path=C:\windows\hosts.exe and one more index=endpoint which shares common field Image_Path and another field MD5 with different time period.
So i need to extract Image_Path value from the index=risk and then it needs to chained to sub-search with index=endpoint + extracted field value | then it needs to be stats Values(Image_Path) by MD5.
Can this be done ?
... View more