Hello, I have a sourcetype called "signons" and it has a field called "Session_ID" and "System_Account" In my search, I am looking for any proxy sessions and want to display those proxy sessions with the same "Session_ID" in the sourcetype called "user_activity". To check if a session is a proxy session, the "System_Account" field has the words "on behalf of". Here is my search so far: index="foo" host="bar" sourcetype="signons" System_Account="*on behalf of*" One example of an event that returns: "System_Account": "12345 / Aaron Cherian on behalf of 67890 / John Doe",
"Authentication_Type": "Proxy Started",
"Session_ID": "4743ha",
"Is_Admin": "1",
"Elapsed_Time_Minutes": "1029" I want to take this Session_ID (There are multiple different Session_ID's because there are many proxy sessions that are being run during the day) and search for the events in a different sourcetype called "user_activity" (This basically checks the user activity for that specific Session_ID. Here is my search for that: index="foo" host="bar" sourcetype="user_activity" 4743ha This is just displaying the events for that specific Session_ID. Is there a way to search for all Session_ID's that have the words "on behalf of" in the "System_Account" field in the "user_activity" sourcetype and display the events? Basically I want to combine these two searches for all proxy Session_ID's Thanks! EDIT: I have posted the same post accidentally under a different category. I am unsure to how to delete it. I apologize for the double post.
... View more