Hi all, i need to take the events from this search
sourcetype="wmi:wineventlog:security"
that have the field Source_Network_Address
into the field DestinationIP
of the search eventtype="searchIPS2" Direction="Inbound" Severity="Medium"
how can i do this? thanks to all who can help me
use subsearch:
eventtype=searchIPS2 Direction=Inbound Severity=Medium [ search sourcetype=wmi:wineventlog:security Source_Network_Address=* | fields Source_Network_Address | rename Source_Network_Address as DestinationIP ]
use subsearch:
eventtype=searchIPS2 Direction=Inbound Severity=Medium [ search sourcetype=wmi:wineventlog:security Source_Network_Address=* | fields Source_Network_Address | rename Source_Network_Address as DestinationIP ]