Hi Wanted to subract the subquery results from main query. i.e
index=main source=/folder/abc.csv |table customername - [index=main source=/folder/xxx.csv |table name ]
can this be achievable ? i want to get only the names which are not common from both the files.
index=main source=/folder/abc.csv OR source=/folder/xxx.csv
| eval name=coalesce(name,customername)
| eventstats dc(source) as flag by name
| where flag=1 AND source="/folder/abc.csv"
| table name
Hi, how about this?
I apologize, there's small change in my question
You gotta do it outside of the subsearch like such.
search abc.csv |table name [search xxx.csv |table name ]
| eval new_field=name_one-name_two
im getting the below error
" 'table' command: Invalid argument: 'name=swbsubwg361'"