Hello, I'm fresh to the ELK but I'm really liking the work with it so far.
I'm current working on a solution that allows us to monitor LDAP logs. and I was wondering if I could display data from several documents in one line. Knowing that they have a field in common.
Here's an exemple to make things clear:
LDAP log lines :
*[04/Aug/2018:22:34:15 +0200] conn=184214 op=-1 msgId=-1 - fd=52 slot=52 LDAP connection from 10.169.146.54:3625 to 10.68.27.65
*[04/Aug/2018:22:34:15 +0200] conn=184214 op=0 msgId=1 - BIND
dn="cn=azerty,ou=manager,o=s" method=128 version=3
*[04/Aug/2018:22:34:15 +0200] conn=184214 op=0 msgId=1 - RESULT err=0 tag=97 nentries=0 etime=0.000450 dn="cn=poiuyr,ou=manager,o=s"
Knowing that every field in this log document is well filtered using the grok pattern. I want to display for example in one chart the IP address of connection(10.169.146.54), the BIND message(dn="cn=azerty,ou=manager,o=s) and the etime of the result (etime=0.000450). and the common field of everything is the conn number("conn=184214")
Currently in the chart that is provided in the discovery mode I only get the fields that are in the same document.
Thank you very much for the help !