I'm new to Elasticsearch. I am finding a solution that can help to perform log correlation. Here's my situation.
I have a application using window event as log. In the window event log, it includes user name and action etc. I would like to know if Elastic can get the Active Directory user info (e.g. display name, department etc.). After that, correlate with the application window event log to show the user belong to which department. Sounds like join function.
Let say I have a win event log include user name Tom. I have a csv file that include name and department e.g. Tom | Accounting. after I add the log and file to elasticsearch, how can I match boths log source and show the win event log Tom is under Accounting?
Thanks for your info but i don't need group by. For an example, I want the table can be shown as below. the field user and eventid are come from win event log, the field department is com from a csv file. Thanks
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.