Hello everybody,
I have many messages with two different source types and an ID and a information field. For every ID, there is one message from source 1 and one from source 2. I need to display to every ID the information field of both source types:
Example:
1 | info field from source 1 | info field from source 2 |
2 |info field from source 2 | null |
If there is no second event to an ID from the other source, "null" should be displayed.
How can I perform this join/combination?
My try:
index=myindex source1 | table id, infofield1 | join type=outer [search index=myindex source2 |table id, infofield2]
Thank you in advance!
Here's something to try.
index=myindex (source1 OR source2) | stats values(infofield1) as infofield1 values(infofield2) as infofield2 by id | fillnull infofield2