Hi. I have summary index_sum, which has 2 events, 2 attributes:
I have also index2, where a lot of time events are stored. The index time time is important. I want to search the max(A1sum) from indexsum and use this value to filter values from the index2.
something like this:
| where _time>max(A1sum)
can you help me, please, with this problem?
I haven't tested but you can try return command like below-
index=index2 |search _time>[search index=index_sum |stats max(A1_sum) as max|return $max]