
I have tried similar things in the past and they can be super difficult to achieve due to the “fuziness”. Ideally, there is something distinctive that we can hang our hat on, and in this case that’s probably the device IP, and you match on that exactly between the logs. According to the manual “followed by” can have a “within 2 seconds” clause, although I haven’t tried that myself.
So it would be [search1] as s1 followed by [search2] as s2 within 2 seconds on s1.target_ip=s2.target_ip - I think :)
Another thing that I have is done is to work with lists (that get populated from scheduled alerts or reports). You put the candidates based on a search on one list, make sure that gets updated from time to time, and then use that list for your second query, without doing the actual correlation during the search. I don’t think that really works in your use case though, because you are just trying to monitor everything from what I understand.
3 comments