I have two different sources, blacklisted and log. blacklisted source contains all the blacklisted IP Addresses, and log source contains network information of potential sources.
Below is the search command i use, together with the results obtained.
sourcetype="Blacklist" OR sourcetype="log" | eval blacklisted=if(sourcetype=="Blacklist",_raw,null()) | fields - _* | fields blacklisted,SRC
Results: http://tinypic.com/r/11mc5z8/5
What i need to do is to compare the two fields and display which are the IP address that matches, in order words, which IP address in my log matches the blacklisted IP address in my blacklisted.
What i tried doing to get the matching field is to use the below command
sourcetype="Blacklist" OR sourcetype="log" | eval blacklisted=if(sourcetype=="Blacklist",_raw,null()) | fields - _* | fields blacklisted,SRC | eval matches=if(blacklisted==SRC, "match", "no match")
Results: http://tinypic.com/r/10e1q2b/5
What i assume is that they are matching the field SRC which is null, to the field blacklisted, and therefore, return no matches.
May i ask if there is any suggestion to solve this problem?
Thank You.
... View more