Has anyone had to match two fields values using a wildcard in one of the fields values.
My scenario, I have a host field that looks like this host=server1 , I have a dest field like this, dest=server1.www.me & dest=server1.xxx.com & dest=comp1. I'm trying to find all instances where the host field with a wildcard matches the dest field. This is the query I have so far without the filter
index="winevents" host=* | stats dc(dest) as total values(dest) count by host | search total > 1