Hello everybody !
Here is what I have in elasticsearch :
URL access logs with those fields :
SourceIP, SourcePort, DestIP, DestPort, User, SessionID, Fingerprint (made with all the previous fields), URL.
Into the same index I have traffic logs with those fields :
SourceIP, SourcePort, DestIP, DestPort, User, SessionID, Fingerprint (made with all the previous fields), BytesRecived, BytesSent.
I would like to be able to correlate the two logs with the fingerprint so I can see for example a top 10 of the accessed URLs by bytes received or sent.
Is that possible ?