Hi Wanted to subract the subquery results from main query. i.e
index=main source=/folder/abc.csv |table customername - [index=main source=/folder/xxx.csv |table name ]
can this be achievable ? i want to get only the names which are not common from both the files.
index=main source=/folder/abc.csv OR source=/folder/xxx.csv | eval name=coalesce(name,customername) | eventstats dc(source) as flag by name | where flag=1 AND source="/folder/abc.csv" | table name
Hi, how about this?