I have the following data in 2 different indexes that I want to merge based on the common email field.
Index B is a big dataset containing around 125k events. I tried using JOIN- but it has limitation and won't return desired results.
Index A
email event
abc@xyz.com click
Index B
email field2 . field3 . field4 . field5
abc@xyz.com blah . blah . blah blah
Final output should be
email event . field2 . field3 . field4 . field5
@kiranpatil1985,
Try,
(index="A" OR index="B")|stats values(event) as event,values(field2) as field2,.....,values(fieldn) as fieldn by email