Open troyheady2 opened 1 year ago
Hey @troyheady2, great idea! I will try to implement this. In the meantime a quick and dirty way to do this is by adding the hostname in the child and parent fields. Example below
index=main source="xmlwineventlog:microsoft-windows-sysmon/operational" EventCode=1
| rex field=ParentImage "\x5c(?
It would be useful to maintain different trees if the data source contained many hosts or days.
can we add this as Option?
i think it would be easy as adding an extra level of dictionary for each byclause concatenated value (or maybe fast hash)