Can someone help with query?
I have 2 index abc and bcz
From abc index I want to show stats for field1
where field2 from index abc matches with field3 of index bcz
and bcz index field5="value"
what I tried which is not working:
index=abc
| stats count by field1
| join type=inner field2
[search index=bcz
| rename field3 as field2
| where field5="employee_name"]
Try something like this
index=abc [search index=bcz
| where field5="employee_name"
| rename field3 as field2
| fields field2]
| stats count by field1
Try something like this
index=abc [search index=bcz
| where field5="employee_name"
| rename field3 as field2
| fields field2]
| stats count by field1
@ITWhisperer You are awesome, I was so stupid.
Thank you.