Hi,
Below is the query which generates the table output.
index=abc sourcetype=report | table company_id , company_name
OUTPUT
company_id company_name
published1 microsoft
published3 google
Published4 apple
Can someone please help me on how can I get the company_id , company_name is one field. something like below:
Result
published1,microsoft
published23,google
published4,apple
Try this!
(your search)|eval company_join=company_id+company_name|table company_join
published1microsoft
(your search)|eval company_join=company_id+":"+company_name|table company_join
published1:microsoft