I wondering if correlating across 2 unique events using common value is possible.
For example
Event ID 4624 (successful logon) and EventId 4647 (logoff) has common field called LogonID
what would be a search query syntax be where logonID in eventid 4624 matches logonid of event 4647