I have 3 different sources of the same filed. I want to aggregate all the 3 sources and get the distinct count of the field
eg.
sourcetype=source1 | stats dc(userlist)
sourcetype=source2 | stats dc(line.userlist)
sourcetype=source3 | stats dc(line.subject)
Here userlist, line.userlist, line.subject are all the same attributes but being logged differently. Now I want to get the dc of userlist+line.userlist+line.subject. Any help is appreciated.
Assuming that the fields only exist in their respective sourcetypes, you could try something like this
sourcetype=source1 OR sourcetype=source2 OR sourcetype=source3
| eval userlist=coalesce(userlist, line.userlist, line.subject)
| stats dc(userlist)
Assuming that the fields only exist in their respective sourcetypes, you could try something like this
sourcetype=source1 OR sourcetype=source2 OR sourcetype=source3
| eval userlist=coalesce(userlist, line.userlist, line.subject)
| stats dc(userlist)
This works well @ITWhisperer