I am trying to write a query that will find if the same data exists in two fields. What i want to do is search two logs to see if that data exists in each but in each log the field names are different.
Bro file logs names the unique identifier FUID and the email log names it FUIDS but I am trying to write a search that will return me both logs with the same identifier in each. In splunk I would do a join but that isn't a possibility (I don't think) in elastic. So what can I write in Kibana to get both logs returned when the data in each is the same.
Also, if I search for a specific FUID I get both logs, what I really want is a search that will return all logs that contain matching FUID and FUIDS. I am trying to identify all emails with attachments and see the email and attachment in one search without searching individual FUIDS.
Thanks. If I am not being clear please let me know and I will try to clear things up more.