Almost certainly - can you give us a sample query you're working with? Hard to give the best answer otherwise
index="exostar" sourcetype="ExostarFile" Comments=Comm
| JOIN type=left UserEmail [search index=ifed source=ExostarAuditIFED "Comm WBS"=true ]
I want all events where Comments=Comm OR "Comm WBS"=true ]
index=exostar (sourcetype=Exostar_File Comments=Comm ) OR (source=ExostarAudit_IFED "Comm WBS"=true)
I don't understand the intention of
join , how about this?
Events that match either of the two conditions are searched.