ELK index field comparison


(vinothine) #1

Hello all,

I have two indexes one index contains the list of malicious domains(index:malicious index) and other index has the logs from my DNS server(indexname:DNSindex) i need to compare whether the field(domainname) which is in DNSindex has the malicious domain.

How to do it?

Thanks in advance


(swarmee.net) #2

I'd love to know what other people say but from my experience this is not possible with elastic search by itself. A little python to loop through one index and search the other, or a logstash job that uses one index from elastic as input, then runs a query in the filter -- would be the two things I would recommend.


(vinothine) #3

Thanks if it can be done through in kibana using join or nested queries then it would be a convenient method


(system) #4

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.