I'm new to Elasticsearch. I am finding a solution that can help to perform log correlation. Here's my situation.
I have a application using window event as log. In the window event log, it includes user name and action etc. I would like to know if Elastic can get the Active Directory user info (e.g. display name, department etc.). After that, correlate with the application window event log to show the user belong to which department. Sounds like join function.