I have created a join field using below query,
Over the same index I have ingested two sets of data via logstash,
event1: indicators:126.96.36.199 actionn:success
event2: indicator:188.8.131.52 tags:perfume,scan
My desired result should be like if I search for success I should get both event1 and event2 as a result just like SQL since indicators is a parent field of indicator and both are joined.
But I am not getting the result. Help me with your inputs.