HI All,
Need help in comparing 2 fields or join 2 values to build a table for another 2 field.
CODE 1:
index=opennms "Cisco-WLC-AP-DOWN/AP*"
| table AP_NAME, Time,downtime,
OUTPUT 1:
AP_NAME | Time | Ticket_ID |
AP6412 | 3/6/2021 19:11 | INC00001 |
AP6412 | 3/6/2021 18:45 | INC00002 |
AW | 3/6/2021 17:08 | INC00003 |
AE | 3/6/2021 16:29 | INC00004 |
AP6412 | 3/6/2021 15:15 | INC00005 |
AR | 3/6/2021 14:31 | INC00006 |
CODE 2:
index=moogsoft_e2e
| table AP_NAME, Time,Ticket_ID,
OUTPUT 2:
AP_NAME | Time | downtime |
AP6412 | 3/6/2021 19:11 | 4:18:55 |
AB | 3/6/2021 18:02 | 1:21:25 |
AC | 3/6/2021 17:08 | 1:23:45 |
AP6412 | 3/6/2021 10:12 | 7:45:23 |
AP6412 | 3/6/2021 15:15 | 2:21:34 |
AE | 3/6/2021 14:31 | 8:12:23 |
Expected final output Table :
AP_NAME | Time | Ticket_ID | downtime |
AP6412 | 3/6/2021 19:11 | INC00001 | 4:18:55 |
AP6412 | 3/6/2021 15:15 | INC00005 | 2:21:34 |
I want both AP_NAME & Time to match the Ticket_ID & downtime.
Try this
(index=opennms "Cisco-WLC-AP-DOWN/AP*") OR index=moogsoft_e2e
| stats values(*) as * by AP_NAME, downtime
| table AP_NAME, Time,Ticket_ID, downtime