I have 2 fields as below
Field1 Field2
abc abc
def jkl
ghi wxy
jkl
pqr
wxy
I have to compare values in Field1 with all values in Field2 and return "Success" if both are same and "Fail" if both are not same.
Expected Result:
Field1 Field2 Result
abc abc Success
def jkl Fail
ghi wxy Fail
jkl Success
pqr Fail
wxy Success
Index is same with different sourcetypes
Try this!
(your search)|table Field1,Field2|eval Result="Fail"
| join type=left Field1 [search (your search) Field2=*|table Field2
|rename Field2 as Field1|eval Result="Success"]
This assumes you passed a transformational command like stats
to get that table view of your metrics. If so, just append this on and make sure to replace Field1
and Field2
with your column names
| eval Result=if(Field1==Field2,"Success","Fail")
Try this!
(your search)|table Field1,Field2|eval Result="Fail"
| join type=left Field1 [search (your search) Field2=*|table Field2
|rename Field2 as Field1|eval Result="Success"]
Thanks @HiroshiSatoh , I tried this and it is working as expected!!!