Hello, I'm trying to combine different events (with different fields) into one event based on a common field value. Is there an easy way to do this? For example:
(index=data sourcetype=source1) OR (index=customer sourcetype=sourcetype2)
Event from Source 1:
customer#: 12345
billingpackage: fastspeed
speed: 50m
Event from Source 2:
customer#: 12345
address: 1st street noth
zip: 41783
Desired Event:
customer#: 12345
billingpackage: fastspeed
speed: 50m
address: 1st street north
zip: 41783
Thanks in advance for the help!
You were close. Run the query you have then use the stats command to merge the results.
(index=data sourcetype=source1) OR (index=customer sourcetype=sourcetype2)
| stats values(*) as * by customer