index=exostar (sourcetype=Exostar_File Comments=Comm ) OR (source=ExostarAudit_IFED "Comm WBS"=true)
I don't understand the intention of
join , how about this?
Events that match either of the two conditions are searched.
index="exostar" sourcetype="Exostar_File" Comments=Comm
| JOIN type=left UserEmail [search index=ifed source=ExostarAudit_IFED "Comm WBS"=true ]
I want all events where Comments=Comm OR "Comm WBS"=true ]