Is there a way to do this logic either in lucene - in Kibana - or in elastic search natively?
-
Where there are n or more events, in the blue index, where the value of field f is the same?
-
Where there are n or more events, in both the blue and the green index, where the value of field f is the same?
e.g. multiple events from the same source IP; or targeting the same destination IP; or events from different indexes with the same sort of field agreement.
Also what about this?
Where event one has a destination address "d" that is equal to the source address "s" in another event, in the same index, or in a different index.
The use case is for making certain kinds of correlated security alerts.