Hi ,
Search 1:
index="sftp" USER=gradydftsftpdata | table USER, SESSION_ID,USER_IP,date_hour | dedup SESSION_ID,USER_IP
with this search I'm able to get USER,SESSION_ID,USER_IP,date_hour
Search 2:
index="sftp" SESSION_ID=9666 date_hour=3 ACTION != session | table FILE_NAME, _time, USER_IP, ACTION.
with this search i'm able to get the session_id of the a particular session with file_name,_time , user_ip, ACTION.
What i'm trying to get is File_NAME,USER,SESSION_ID,date_hour,USER_IP,ACTION and the search that i'm using is
index=sftp USER=gradydftsftpdata SESSION_ID=* | join sftp[search index=sftp SESSION_ID=* date_hour=* ACTION != session | table FILE_NAME, _time, USER_IP, ACTION] | table FILE_NAME,USER, SESSION_ID,USER_IP,date_hour,_time,ACTION | dedup SESSION_ID,USER_IP
Is this the correct search that i'm using to get output??
... View more