I am working on a query to report on host/s that have triggered two different event types. For example windows event IDs 4697 and 4698, if triggered by the same host, rule must alert.
EventType =4697
EventType =4698
HostName=What is the best way to imply host name being unique to the eventtypes.
To further clarify, if the same host triggers 4697 and 4698 in a 5 minute window, I want to report on that.
Thanks in advance.
index="windows_events" Eventtype=4697 OR Eventtype=4698 |stats count by Hostname