i have two conditions which has to be put in a same search.
conditon no 1:
if the Source address is in bad_ips.csv (lookup)
Number of Alerts received from IPS > 10 queries to DNS from same Source Address in 1 minute
Source Address are selected after comparing with the bad_ips look up .
Condition 2 :
if the source addresses are unknown,then
Number of Alerts received from IPS > 50 queries to DNS from same Source Address in 1 minute
kindly tell me about how to write the above conditions in the same search?
Index=ips (same for both)
Thanks in advance
As with some of your other posts, it's a bit hard to give you a search when you just give us the name of an index and the name of a lookup. Hopefully you understand that that is very little to go on.
So instead let's just talk about the process your search could use and then if you have more details you can share about the data, maybe we can help you actually write the search.
A couple questions. Are you planning to run this search over the past minute? Or do you want to run it over a longer period of time but do your evaluations in a minute interval? That will affect how the search is done.