Correlate events

Hi Folks,

I wondering if correlating across 2 unique events using common value is possible.
For example
Event ID 4624 (successful logon) and EventId 4647 (logoff) has common field called LogonID

what would be a search query syntax be where logonID in eventid 4624 matches logonid of event 4647


That’s not possible with Graylog at the moment, but Graylog 3.0.0 might come with some new features enabling this kind of query.


Such a tease! Come on @jochen you know you want to tell us the new feature!

