Hello Experts, We are having an issue where we are having two indexes named monitor and poll. Below is the structure of both the indexes.
Monitor:
hostname,ip_address,monitored,tool
poll:
machinename, lastpoll
Our requirement is to take each hostname from monitor index and compare with poll index and if hostname(monitor) matches with machinename(poll) then it has to list all the fields from both the index.
How can we achieve it. Kindly help us.
Thanks
Here's one approach.
index=monitor OR index=poll
| eval machine=coalesce(hostname, machinename)
| stats values(ip_address) as ip_address, values(monitored) as monitored, values(tool) as tool, values(lastpoll) as lastpoll by machine