I have an index with below fields and data set,
1.indicator:188.8.131.52 action:success 2.indicators:184.108.40.206 tags:elk-search 3.indicator:220.127.116.11.84 action:success
I have built a dashboard for the above with 4 panels indicator,indicators,action and tags.
Now if I search for success only 2 panels are filtering data i.e,
But I wanted data in 4 panels because success is related to 18.104.22.168 and the IP is present in one more meta called indicators which is related to tags.
To summarize if i filter success in my dashboard I need to get the below correlated data,
indicator:22.214.171.124 action:success indicators:126.96.36.199 tags:elk-search
Is there any ways to achieve this using ELK queries? Kindly suggest your ideas as I am a beginner in writing queries.