Document toolboxDocument toolbox

Cross-Search Table Join

Overview

Use this option to combine and compare the data from two or more separate tables that share a common field.

What data do I need for this widget?

In order to generate the cross-search table join, you need to run at least two queries with at least three columns, one of them numerical and one of them in common. Furthermore, those queries need to have the data grouped for the diagram to show meaningful data.

Creating a Cross-Search Table Join

Query example

You can use the following queries to recreate the example shown in the images above:

from siem.logtrust.web.activity group every 5m by responseLength, username, correlationId every 5m select count() as count
from siem.logtrust.web.navigation group every 5m by userEmail, action, srcPort every 5m select count() as count