I need to find events in Index B that happened withing 5 minutes of events in Index A.
Unfortunately I do not have anyway to join them other than time ranges. Can you help me figure this out?
Try this:
index=A something | localize timebefore=5m timeafter=5m | map search="search earliest=$starttime$ latest=$endtime$ index=B"
Try this:
index=A something | localize timebefore=5m timeafter=5m | map search="search earliest=$starttime$ latest=$endtime$ index=B"
That worked! Thank you!!!!