Correlate events

(Nav) #1

Hi Folks,

I wondering if correlating across 2 unique events using common value is possible.
For example
Event ID 4624 (successful logon) and EventId 4647 (logoff) has common field called LogonID

what would be a search query syntax be where logonID in eventid 4624 matches logonid of event 4647


(Jochen) #2

That’s not possible with Graylog at the moment, but Graylog 3.0.0 might come with some new features enabling this kind of query.


Such a tease! Come on @jochen you know you want to tell us the new feature!

(system) closed #4

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.