I have a query that is able to join two or more source types with the same log format in each source log (all log with key=value pair format). However, I am having difficulties to join two or more source types if the source logs are not in the same format (e.g., one source log is in json format and the other is in key=value pair format).
All logs are joined by the id key name found in each source log.
This is main construct to join two source types with the same key=value pair format:
(sourcetype="request" AND application=vsp NOT (Agent.007) ) OR
first(key_name1) as key1
list(key_name2) as key2
dc(sourcetype) as dc by id|
Can anyone share any example to join one source log with json format and another source log with key=value pair format a common key name?