Correlate events

Hi Folks,

I wondering if correlating across 2 unique events using common value is possible.
For example
Event ID 4624 (successful logon) and EventId 4647 (logoff) has common field called LogonID

what would be a search query syntax be where logonID in eventid 4624 matches logonid of event 4647


That’s not possible with Graylog at the moment, but Graylog 3.0.0 might come with some new features enabling this kind of query.

1 Like

Such a tease! Come on @jochen you know you want to tell us the new feature!

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.