I have an index with below fields and data set,
1.indicator:184.108.40.206 action:success 2.indicators:220.127.116.11 tags:elk-search 3.indicator:18.104.22.168.84 action:success
I have built a dashboard for the above with 4 panels indicator,indicators,action and tags.
Now if I search for success only 2 panels are filtering data i.e,
But I wanted data in 4 panels because success is related to 22.214.171.124 and the IP is present in one more meta called indicators which is related to tags.
To summarize if i filter success in my dashboard I need to get the below correlated data,
indicator:126.96.36.199 action:success indicators:188.8.131.52 tags:elk-search
Is there any ways to achieve this using ELK queries? Kindly suggest your ideas as I am a beginner in writing queries.