# Compare two fields in SIEM

**URL:** <https://discuss.elastic.co/t/compare-two-fields-in-siem/253927>\
**Category:** SIEM\
**Created:** [November 1, 2020, 6:24am UTC](https://discuss.elastic.co/t/compare-two-fields-in-siem/253927 "2020-11-01T06:24:58Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Post date:** [November 1, 2020, 6:24am UTC](https://discuss.elastic.co/t/compare-two-fields-in-siem/253927/1 "2020-11-01T06:24:58Z")

</div>

Hi,  
I want to trigger an alarm if two fields have the same value. is it possible or I have to use watcher?

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [November 2, 2020, 5:48pm UTC](https://discuss.elastic.co/t/compare-two-fields-in-siem/253927/2 "2020-11-02T17:48:31Z")

</div>

Are you currently using our detections/alerts yet?

> **[Detections and Alerts (beta) | Elastic Security Solution \[7.9\] | Elastic](https://www.elastic.co/guide/en/security/current/detection-engine-overview.html)**

---

<div class="post-metadata">

**Author:** ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Post date:** [November 7, 2020, 5:02am UTC](https://discuss.elastic.co/t/compare-two-fields-in-siem/253927/3 "2020-11-07T05:02:18Z")

</div>

> [@Frank\_Hassanabad](#):
>
> Are you currently using our detections/alerts yet?

Yes, currently I'm using the trial license. but I still couldn't produce any signal by creating a rule like: `fieldx : fieldy`

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [November 9, 2020, 3:47pm UTC](https://discuss.elastic.co/t/compare-two-fields-in-siem/253927/4 "2020-11-09T15:47:39Z")

</div>

I think I might be seeing what you're asking for maybe?

Right now you can do something like this with detection rules and a KQL rule to find a specific value:

```json
host.name: "my_specific_host_value"

```

But you're wanting to use an index and its fields as dynamic input like so:

```json
host.name: "my_index.host.name"

```

And then if "my\_index.host.name" has 1 or more values it will find any signals based on those values dynamically each time the rule is run by querying against each of those `my_index.host.name`'s.

Is that it?

---

<div class="post-metadata">

**Author:** ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Post date:** [November 9, 2020, 4:33pm UTC](https://discuss.elastic.co/t/compare-two-fields-in-siem/253927/5 "2020-11-09T16:33:22Z")

</div>

No, it's much simpler.  
I want to compare to fields of the same doc. for example if in any doc, `user.name` = `host.name` then trigger a signal.

---

<div class="post-metadata">

**Author:** ![yctercero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yctercero/32/68560_2.png) [@yctercero](https://discuss.elastic.co/u/yctercero)\
**Post date:** [November 9, 2020, 6:45pm UTC](https://discuss.elastic.co/t/compare-two-fields-in-siem/253927/6 "2020-11-09T18:45:19Z")

</div>

Hey @borna_talebi ! We don't currently have that functionality, but that's interesting. If you don't mind sharing, what's your particular use case?

---

<div class="post-metadata">

**Author:** ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Post date:** [November 11, 2020, 5:10am UTC](https://discuss.elastic.co/t/compare-two-fields-in-siem/253927/7 "2020-11-11T05:10:40Z")

</div>

Hi Yara,  
My use case is to detect zerologon exploit using [winlogbeat events](https://www.kroll.com/en/insights/publications/cyber/cve-2020-1472-zerologon-exploit-detection-cheat-sheet). I'm not sure if this functionality is or will be available in EQL but I'm hoping it'll be added.

---

<div class="post-metadata">

**Author:** ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)\
**Post date:** [November 11, 2020, 7:52am UTC](https://discuss.elastic.co/t/compare-two-fields-in-siem/253927/8 "2020-11-11T07:52:22Z")

</div>

I needed something similar for source.ip = destination.ip

Sometimes events trigger on a host to themselves.

My solution so far was to use logstash

If [event][code] == 3 {

If [source][ip] == [destination][ip] {

To then tag the event and the alert is based on the tag.

Have to use a condition before this to make sure destination or source exists. Otherwise I found it tagged all events without the fields and worked correctly when source and destination present.

---

<div class="post-metadata">

**Author:** ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Post date:** [November 11, 2020, 8:28am UTC](https://discuss.elastic.co/t/compare-two-fields-in-siem/253927/9 "2020-11-11T08:28:54Z")

</div>

Tnx Philip, I'll check this out. But I still think a faster and easier way to achieve this without the need to edit data and add tags would be great!

---

<div class="post-metadata">

**Author:** ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)\
**Post date:** [November 12, 2020, 10:27am UTC](https://discuss.elastic.co/t/compare-two-fields-in-siem/253927/10 "2020-11-12T10:27:36Z")

</div>

No problem, not the best solution. However with the new corrolation rules in 7.10 with EQL it maybe possible, something else to now learn.

---

<div class="post-metadata">

**Author:** ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Post date:** [November 15, 2020, 8:32am UTC](https://discuss.elastic.co/t/compare-two-fields-in-siem/253927/11 "2020-11-15T08:32:32Z")

</div>

> [@probson](#):
>
> However with the new corrolation rules in 7.10 with EQL it maybe possible

According to [docs](https://www.elastic.co/guide/en/elasticsearch/reference/master/eql-syntax.html) it's not possible:

> You also **cannot** use comparison operators to compare a **field** to another **field**. This applies even if the fields are changed using a [function](https://www.elastic.co/guide/en/elasticsearch/reference/master/eql-syntax.html#eql-functions).

I really hope they add this feature.

---

<div class="post-metadata">

**Author:** ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)\
**Post date:** [November 16, 2020, 8:46am UTC](https://discuss.elastic.co/t/compare-two-fields-in-siem/253927/12 "2020-11-16T08:46:05Z")

</div>

Isnt this what you were after?

> **[EQL syntax reference | Elasticsearch Reference \[master\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/master/eql-syntax.html)**

**Example**  
The following EQL query compares the `process.parent_name` field value to a static value, `foo` . This comparison is supported.

However, the query also compares the `process.parent.name` field value to the `process.name` field. This comparison is not supported and will return an error for the entire query.

```auto
process where process.parent.name == "foo" and process.parent.name == process.name

```

Instead, you can rewrite the query to compare both the `process.parent.name` and `process.name` fields to static values.

---

<div class="post-metadata">

**Author:** ![borna\_talebi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borna_talebi/32/76317_2.png) [@borna\_talebi](https://discuss.elastic.co/u/borna_talebi)\
**Post date:** [November 16, 2020, 8:49am UTC](https://discuss.elastic.co/t/compare-two-fields-in-siem/253927/13 "2020-11-16T08:49:19Z")

</div>

> [@probson](#):
>
> This comparison is **not supported** and will return an **error** for the entire query

This is what I want but as you can see it's not supported.

---

<div class="post-metadata">

**Author:** ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)\
**Post date:** [November 16, 2020, 11:50am UTC](https://discuss.elastic.co/t/compare-two-fields-in-siem/253927/14 "2020-11-16T11:50:59Z")

</div>

Sorry i didnt notice that bit, typical. I thought i had used it last week but i used 2 sequences, one tracks process.pid and the other the process.parent.pid. Wires crossed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2020, 11:51am UTC](https://discuss.elastic.co/t/compare-two-fields-in-siem/253927/15 "2020-12-14T11:51:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
