I'm doing some tests with ELK (Latest version), here is my use case:
I'm indexing some documents containing phone activity, where I use these fields:
- SYSTEMA.Call Direction
On other side, I'm also indexing similar documents
- SYSTEMB.Call Direction
My target is to search for any SYSTEMA document if a similar SYSTEMB document exists (With same EndUserName, EndUserPhoneNumber, CounterpartPhoneNumber, CallDirection) and approximatively same date (With few second of difference).
I thought about creating a scripted field for SYSTEMA checking the existence of a similar SYSTEMB document, what do you think?
Do you have another way to achieve this?