I was just wondering if there is a way to compare field values in two different streams.
For context I have firewall logs coming in and am filtering all denied connections into a stream as they are mostly port scanning, I would like to filter all the other messages from the firewall logs into a stream. I would then like to see if any of the denied IPs have been accepted and this would allow me to see where these port scanning IPs have been allowed access into the network. I would then also be able to look at IIS logs to see any other actions these IPs have been taking.

Have a look at @billmurrin’s slookup plugin. This should help you if I understood your question correctly :slight_smile:

Thankyou for the suggestion, I will get around to looking into it and give you an update on whether it solved my problem :slight_smile:


