We need to create alarms based on matches, where only certain criteria will be available in a log, but the complimenting information will reside in additional logs that have the same ID.
For instance, take 10 logs, which have a common ID. We would like to match one field, which could potentially match serveral logs, with different IDs. Then we would like to iterate over those IDs and see if additionally matches exist. If so, trigger the alarm.
Take for example the following documents:
ID=1, Name=foo, Type=bar
ID=2, Name=foo, Type=baz
We would like to match on Name=foo and LastName=booz, but not on Name=foo and LastName=chaz.
Any ideas on how we could achieve this?