Hi All,
I need some advice or help,
so I have 2 index I'd like to join but it seems not working as I expected :
index a
| name | info |
| person1 | aa-bb-cc |
| person2 | bb-cc-dd |
| person3 | cc-dd-ee |
| thing1 | dd-ee-ff |
index b
| identifier | note |
| aabbcc | this is good |
| bbccdd | this is bad |
| ccddee | this is good |
Id like to make the result below
| name | info | note |
| person1 | aa-bb-cc | this is good |
| person2 | bb-cc-dd | this is bad |
| person3 | cc-dd-ee | this is good |
What I currently have is:
index=a
| search name=person*
| eval identifier=replace(info, "-","")
| join type=outer identifier [search index=b]
| table name info note
But I still find the result "note" field is empty/null
did I miss something in this search ?
Try without using join
index=a OR index=b
| eval identifier=if(isnull(identifier),replace(info, "-",""),identifier)
| stats values(*) as * by identifier
| search name=person*
| table name info note