I have two indexes and I want to display events from both indexes in chronological order, filtering by a specific IP. What is the simplest way to accomplish this?
Thanks,
Jonathan
Are you just looking to see all of the raw events for those 2 indexes for a specific IP?
If so then something simple like this should give you what you need:
index=index1 OR index=index2 IP="10.10.210.1"
Are you just looking to see all of the raw events for those 2 indexes for a specific IP?
If so then something simple like this should give you what you need:
index=index1 OR index=index2 IP="10.10.210.1"
That's exactly what I was looking for. I didn't realize it was that simple. Thanks!
You can do a sub-search across both indexes
index=index1 IP="123.34..56.192" Field="*" [search index=index2 IP="123.34..56.192" Field="*"] | stats count by IP
Thanks for the response. I tried your query, but I got no events back even though both of the following queries returns events:
index=index1 IP="XXX"
index=index2 IP="XXX"
Any ideas on why this might not be working?
Thanks,
Jonathan
index1
, index2
,Field
, IP
are just place holder names I put in there. You should use your index names and fields. Give me a sample of your data and I'll help build the query. You will need both index names and a common IP field which is present in both indexes
I understand. I just didn't want to reveal proprietary information, like our customers' IP addresses. 🙂
When I use the actual IP address, and the real index names, I get no records returned.