Hi,
I have a request where in
1.I will have to perform a search to get value A,B and C (where B is the values of the field that i created using regex)
2.Based on the values of B -> I will have to perform another search in completely different index and get the values of E and F
3.And also based on the values of B -> I will have to perform another search in completely different index and get the values of G and H
4.Finally i should have table with A B C E F G H
I tried using join concept but the common field between 1st and 2nd search is B and B is the field that i extracted using rex.
I'm not because of that reason it is working or not,I'm getting ) results.
Kindly help!
Thanks!
@Deepz2612
You can use append
and stats
for same. Please refer below sample search for same.
index=a | fields A B C
append [ search index=b | fields B E F ]
append [ search index=c | fields B G H ]
| stats values(A) as A values(C) as C values(D) as D values(E) as E values(F) as F values(G) as G values(H) as H by B
| table A B C D E F G H
Thanks!
But i wanted to perform 2nd and 3rd search based on the values of B that i get from 1st search