Hi All,
our SVC calculation is in _introspection and and our search name is in _internal and _audit. We need a common filed to map those together so we can tie an SVC (and dollar amount) to a particular search. We tried doing it using the SID but that is not matching.
Can someone help me out here based on your experiences.
Hi @sairajkiran
Try checking the values from the job inspector for your event/search. Not sure if it will fulfil your needs.
The field you can use is search_id -- in _introspection and _audit indexes
For _internal, you'll need to extract this value from job which looks something like this search/search/jobs/1710936732.74/control
so the search_id field value is 1710936732.74
If the reply helps, a Karma vote would be appreciated.