Combine / Correlate different logs

(Micke) #1

For now i am using the filebeat and winlogbeat agents to collect data, which collects events in different indexes (indicies?).

I i want to combine searches from both sources to find a correlation when troubleshooting a problem? How do i do this? When i search i have to specify the index.

(Mark Walkom) #2

You can create dashboards with visualisations from across different index patterns.
Does that help?

(Micke) #3

If that is the way to do it, i guess that will help.

Is there any other way? If not, thanks

(system) #4

