I'm trying to return a list of values from a subsearch to compare that list to other field values in main search. It should look like this:
sourcetype=any OR sourcetype=other
|eval test =[search sourcetype=any OR sourcetype=other
|streamstats count by field1, field2
|stats values(field1) AS f1 values(field1) AS f2
|eval status =if(match(f2,f1),"True","False")
|where status ="False"
|stats values(field3) as f3
|where field4 = test
Hello,sry that my question above is a bit complicated to understand.What I want to do is this:
I'm indexing data from two different sourcetypes that have some similar data in different fields. Now I want to compare the values of two fields (field1 and field2) and check if there are some equal values and get a list of that equal values (lets call it "VALUELIST"). Then i want to compare other field values (from field3 and field4) of events that have one of the values from VALUELIST in their field1 or field2. At the end i need a table with values from VALUE_LIST, field3 and field4 where field3 and field4 are not eqaul. Thanks for the help!