source A : filename,title,version,type,date
source B: filename,date
I want to compute the title field for source b and output that into my data where the file name has the same value for source A and B.
Goal: source=b | table _time,filename,title
Where source b does not include the title in the _raw but source a has the same filename and also includes title in the _raw.
Try this:
(source=A OR source=B) | stats latest(_time) as _time, latest(title) as title by filename | table _time, filename, title
Try this:
(source=A OR source=B) | stats latest(_time) as _time, latest(title) as title by filename | table _time, filename, title
This works, but what I really want is for the events to become a new field in the search, because now I cannot add other fields lost to the stats pipe. For example, I want: | table _time,filename,title,version,w_day
To avoid losing fields to stats
, include them in stats
. ... | stats latest(_time) as _time, latest(title) as title latest(version) as version, latest(w_day) as w_day by filename | ...
.
Thanks @richgalloway. I thought enough to do that, but my mistake was not carrying the by clause to the end. Makes sense to me now. Thank you.