Hello, I have a data model named firewall_logs with firewall data in which the interesting fields are: file_hash, url and source/dest IP.
And I have a dataset named intel_indicators with column named ioc in which I have hashes, IPs, domains and timestamp.
What I want to do is to compare the data (hashes, IPs, domains) from ioc column with the fields: file_hash, url, dest_ip. If there is a match, it should be visible.
Any ideea how I can accomplish this ?
| tstats summariesonly=t allow_old_summaries=t ...interesting fields.... from datamodel="firewall_logs" a
and here I'm stuck
... View more