hi, i'm struggling to sort out how to get a query to work.
I have two sites sending logs via filebeat into an ELK stack.
Each entry will have a field called "site" along with a bunch of log info (ip address, port, etc)
what i'd like to do is have a query that shows ip addresses that appear at both sites, and how many times they hit the sites.
Site1 Count: 153
Site2 Count: 27
any suggestions on how i could do this?