Basically I am trying to see if there is a way to do an eval to grab a field value from two different events. For example lets say I have:
Application=Chrome Note=this is an application
Application=Chrome Note=this is an application2
So I want to see if there is a way to make a new field where Application=Chrome that combines the two notes together into another field. so it'd add a field that is like Newnote=this is an application this is an applcation2.
Are you looking for the following?
| stats list(Note) as NewNote by Application
When there is an similar Application comes all the notes will be added into Newnote field.
Try the below search,
... your base search | eventstats values(Note) as Newnote by Application | nomv Newnote
Hope this will helps you.
Are you looking for the following?
| stats list(Note) as NewNote by Application
Thank you this worked 🙂