Is there a way to create a single event including fields from multiple different sources?
The use case is alerting on VPN login. The messages from my USG show the remote IP, but doesn’t include the user. The messages from my DC show the user, but not the remote IP.
The two messages are typically separated by less than 5s.
I’d like to be able to get a single alert with both the IP and username. In the rare case that two users connect within a few seconds, I’d be ok with bad or no correlation between IPs and users (in my case, they’d almost certainly be from the same remote IP anyway).
I have the search working: (source:DC01 and Security_ID:*) OR (source:UnifiGateway AND "Connection established"), but I can only pull a field from one or the other.