I want to keep it in field A (or any other field) only if there is a matching column in field A and field B, as shown in the figure below. It seems good to use the "foreach" statement, but I don't know how to implement it.
No | Field A | Field B |
1 | 100 | |
2 | 200 | |
3 | 300 | |
4 | 100 | |
5 | 4000 | |
6 | 5000 |
Extract only the No. 1 column.
No | Field A | Field B |
1 | 100 |
Hi please try something like this:
your_search
| eval no_field1=no, field_merged=coalesce(field1, field2)
| stats values(no_field1) AS no values(field1) AS field1 count BY field_merged
| where count>1
| table no field1
Ciao.
Giuseppe