Is it possible to have a joined search with condition A in the first search OR condition B in the second search?
Retrieve events from the index
index=exostar (sourcetype=Exostar_File Comments=Comm ) OR (source=ExostarAudit_IFED "Comm WBS"=true)
I don't understand the intention of join
, how about this?
Events that match either of the two conditions are searched.
second search is a subsearch
index="exostar" sourcetype="Exostar_File" Comments=Comm
| JOIN type=left UserEmail [search index=ifed source=ExostarAudit_IFED "Comm WBS"=true ]
I want all events where Comments=Comm OR "Comm WBS"=true ]
Almost certainly - can you give us a sample query you're working with? Hard to give the best answer otherwise