I have two fields in two different log lines and want result something like below sample table :-
product_code_pause | count | product_code_unpause | count |
1234567 | 3 | 1234567 | 2 |
How can I achieve this by updating below query :-
("Pause entry") OR ("Paused Entry added back to cart successfully : ") | rex field=_raw "product : (?<product_code_pause>(?:[^,]+))" | rex field=_raw "successfully : (?<product_code_unpause>(?:[^,]+))" | stats count by product_code_pause,product_code_unpause