I have data in three source types to co-relate. Time and a unique identifier number are common for all three sourcetype data.
Sample data from the first sourcetype:
_time unique_number Name
12/9/2019 9:49 4782 John
12/9/2019 9:52 698 Andrew
12/9/2019 9:56 2487 Marshal
I need to check whether John is having a unique number 4782 in the rest of the two tables within the last 20 minutes of 1st sourcetype data time aka John's time (i.e.: 12/9/2019 9:49).
If any match found, need to return a comment(matched/not matched) to main search (i.e.: table _time,unique_number,Name,comment.
I tried sub search with join but definitely missing some points and not getting the desired output.