Hi All,
I need some advice or help,
so I have 2 index I'd like to join but it seems not working as I expected :
index a
name | info |
person1 | aa-bb-cc |
person2 | bb-cc-dd |
person3 | cc-dd-ee |
thing1 | dd-ee-ff |
index b
identifier | note |
aabbcc | this is good |
bbccdd | this is bad |
ccddee | this is good |
Id like to make the result below
name | info | note |
person1 | aa-bb-cc | this is good |
person2 | bb-cc-dd | this is bad |
person3 | cc-dd-ee | this is good |
What I currently have is:
index=a
| search name=person*
| eval identifier=replace(info, "-","")
| join type=outer identifier [search index=b]
| table name info note
But I still find the result "note" field is empty/null
did I miss something in this search ?
Try without using join
index=a OR index=b
| eval identifier=if(isnull(identifier),replace(info, "-",""),identifier)
| stats values(*) as * by identifier
| search name=person*
| table name info note