I have a scenario to extract a particular set id's from index1 in search1 and run a search2 on index2 based on the extracted ids.
index="index1" sourcetype="st1" field1="abc"
|rename id as ticket_id
| sort 0 ticket_id
What's the best way to go about it? I tried using map but I've had no luck at all. Not sure if it's because I'm using it wrong or if it's not appropriate for the situation. Including both indexes at the start of the search is not feasible given the absurd size of the second index.
Can anyone please help me here?
Thank you in advance.
If the number of results from search 1 is fewer than 10,000 then you can use a subsearch.
index="index2" source="xyz" [ index="index1" sourcetype="st1" field1="abc" |rename id as ticket_id | fields ticket_id | format ] | sort 0 ticket_id |.........