HI All,
Need help in comparing 2 fields or join 2 values to build a table for another 2 field.
CODE 1:
index=opennms "Cisco-WLC-AP-DOWN/AP*"
| table AP_NAME, Time,downtime, 
OUTPUT 1:
| AP_NAME | Time | Ticket_ID | 
| AP6412 | 3/6/2021 19:11 | INC00001 | 
| AP6412 | 3/6/2021 18:45 | INC00002 | 
| AW | 3/6/2021 17:08 | INC00003 | 
| AE | 3/6/2021 16:29 | INC00004 | 
| AP6412 | 3/6/2021 15:15 | INC00005 | 
| AR | 3/6/2021 14:31 | INC00006 | 
CODE 2:
index=moogsoft_e2e
| table AP_NAME, Time,Ticket_ID,
OUTPUT 2:
| AP_NAME | Time | downtime | 
| AP6412 | 3/6/2021 19:11 | 4:18:55 | 
| AB | 3/6/2021 18:02 | 1:21:25 | 
| AC | 3/6/2021 17:08 | 1:23:45 | 
| AP6412 | 3/6/2021 10:12 | 7:45:23 | 
| AP6412 | 3/6/2021 15:15 | 2:21:34 | 
| AE | 3/6/2021 14:31 | 8:12:23 | 
Expected final output Table :
| AP_NAME | Time | Ticket_ID | downtime | 
| AP6412 | 3/6/2021 19:11 | INC00001 | 4:18:55 | 
| AP6412 | 3/6/2021 15:15 | INC00005 | 2:21:34 | 
I want both AP_NAME & Time to match the Ticket_ID & downtime.
Try this
(index=opennms "Cisco-WLC-AP-DOWN/AP*") OR index=moogsoft_e2e
| stats values(*) as * by AP_NAME, downtime
| table AP_NAME, Time,Ticket_ID, downtime